VYPR

CWE-134

Use of Externally-Controlled Format String

BaseDraftLikelihood: High

Description

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-135 · CAPEC-67

CVEs mapped to this weakness (400)

page 1 of 20
  • CVE-2024-23113CriKEVFeb 15, 2024
    risk 0.81cvss 9.8epss 0.62

    A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0…

  • CVE-2019-1579HigKEVJul 19, 2019
    risk 0.74cvss 8.1epss 0.46

    Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

  • CVE-2020-13160CriJun 9, 2020
    risk 0.73cvss 9.8epss 0.81

    AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.

  • CVE-2020-3118HigKEVFeb 5, 2020
    risk 0.70cvss 8.8epss 0.12

    A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from…

  • CVE-2018-6317CriFeb 2, 2018
    risk 0.66cvss 9.1epss 0.44

    The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service.

  • CVE-2026-50211CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

  • CVE-2023-53966CriDec 22, 2025
    risk 0.64cvss 9.8epss 0.01

    SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to…

  • CVE-2012-10055CriAug 13, 2025
    risk 0.64cvss epss 0.02

    ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending a specially crafted username containing format specifiers, a remote attacker can overwrite a hardcoded function pointer in memory (specifically…

  • CVE-2025-40600CriJul 29, 2025
    risk 0.64cvss 9.8epss 0.01

    Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

  • CVE-2025-46121CriJul 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can…

  • CVE-2023-5746CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.5-0185 may be affected:…

  • CVE-2023-35087CriJul 21, 2023
    risk 0.64cvss 9.8epss 0.01

    It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote…

  • CVE-2022-35877CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An…

  • CVE-2022-35876CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An…

  • CVE-2022-35875CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An…

  • CVE-2022-35874CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An…

  • CVE-2022-35244CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a…

  • CVE-2022-33938CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption, information disclosure and denial of service. An attacker…

  • CVE-2022-34747CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.02

    A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.

  • CVE-2022-26674CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.03

    ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.