Flaw in Progress LoadMaster exploited in attacks
CISA warns of active exploitation of critical command injection flaw in Progress Kemp LoadMaster; urges patching.
16 results for “command injection”
CISA warns of active exploitation of critical command injection flaw in Progress Kemp LoadMaster; urges patching.
A critical command injection vulnerability in the MSI RadiX AXE6600 router allows remote attackers to execute arbitrary code and gain root access.
A critical vulnerability in the MSI Radix AXE6600 router allows remote attackers to gain root access via the wps.cgi interface.
A critical command injection vulnerability in Progress LoadMaster is under active exploitation, prompting urgent CISA remediation requirements.
Puwell IP cameras running firmware versions 2.x through 4.x are vulnerable to unauthenticated remote code execution via a flaw in the DebugShell interface.
A critical remote command injection vulnerability in GL.iNet GL-MT3000 routers allows unauthenticated attackers to execute arbitrary code on affected devices.
A severe RCE vulnerability in GL-MT3000 routers allows unauthenticated remote attackers to execute arbitrary system commands.
A critical vulnerability allows unauthenticated attackers to execute arbitrary commands as root, earning a maximum CVSS score of 9.8.
A critical shell command injection flaw in IBM Aspera Faspex 5 allows remote authenticated attackers to execute arbitrary code with high-level privileges.
A critical OS command injection vulnerability in Arista VeloCloud Orchestrator is now confirmed to be exploited in the wild.
A critical vulnerability in Microsoft Kiota allows attackers to execute arbitrary code via malicious OpenAPI descriptions processed by the tool.
A critical vulnerability in AVideo allows for arbitrary OS command execution, bypassing previous security mitigations.
Federal agencies must address a critical OS command injection vulnerability in Fortinet products by July 19, 2026.
Federal agencies must address an actively exploited OS command injection vulnerability in Fortinet products by July 19, 2026.
CISA has confirmed active exploitation of an OS command injection vulnerability in Fortinet FortiSandbox, mandating urgent remediation for federal agencies.
Thousands of Hikvision devices remain vulnerable to a critical command injection flaw, drawing attention from global threat actors.