CVE-2024-28328
CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client nam
CVSS
5.4
Medio
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Publicado: 26 abr 2024 · Última mod.: 9 jul 2026 · CWE-77
0.4%EPSS · 30 días0.4%
2026-08-222026-09-19
CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.
- github.comhttps://github.com/ShravanSinghRathore/ASUS-RT-N300-B1/wiki/CSV-Injection-CVE%E2%80%902024%E2%80%9028328
- github.comhttps://github.com/ShravanSinghRathore/ASUS-RT-N300-B1/wiki/CSV-Injection-CVE%E2%80%902024%E2%80%9028328
- redfoxsec.comhttps://redfoxsec.com/blog/asus-rt-n12-b1s-csv-injection-cve%E2%80%902024%E2%80%9028328/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-937429.9 CRÍ78.5%
——24A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.20hCVE-2026-935336.3 MED64.6%
——19A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.1dCVE-2026-886228.8 ALT63.8%
——19NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.2dCVE-2026-933718.3 ALT70.3%
——21A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The name of the patch is c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897. A patch should be applied to remediate this issue.2dCVE-2026-858859.9 CRÍ43.7%
——13Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.1dCVE-2026-785017.4 ALT41.0%
——12Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.2d