VYPR

CWE-15

External Control of System or Configuration Setting

BaseIncomplete

Description

One or more system settings or configuration elements can be externally controlled by a user.

Allowing external control of system settings can disrupt service or cause an application to behave in unexpected, and potentially malicious ways.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-146 · CAPEC-176 · CAPEC-203 · CAPEC-270 · CAPEC-271 · CAPEC-579 · CAPEC-69 · CAPEC-76 · CAPEC-77

CVEs mapped to this weakness (94)

page 4 of 5
  • CVE-2025-30512MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

  • CVE-2023-43323MedSep 28, 2023
    risk 0.42cvss 6.5epss 0.02

    mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].

  • CVE-2026-43531HigMay 5, 2026
    risk 0.40cvss 7.3epss 0.00

    OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Attackers can inject variables affecting update sources, gateway URLs, ClawHub resolution, and browser executable paths to…

  • CVE-2025-27253MedMar 10, 2025
    risk 0.40cvss 6.1epss 0.00

    A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that establishes a TCP connection through a port forwarding. The lack of the IP address and port validation may…

  • CVE-2025-62527HigOct 20, 2025
    risk 0.39cvss 7.1epss 0.00

    Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset email containing a malicious link, allowing the attacker to set the email if clicked by the victim.…

  • CVE-2026-30817MedApr 8, 2026
    risk 0.37cvss 5.7epss 0.00

    An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary…

  • CVE-2026-30816MedApr 8, 2026
    risk 0.37cvss 5.7epss 0.00

    An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary…

  • CVE-2026-22169MedMar 18, 2026
    risk 0.37cvss 6.7epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass…

  • CVE-2026-32003MedMar 19, 2026
    risk 0.36cvss 6.6epss 0.01

    OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypass command allowlist restrictions via SHELLOPTS and PS4 environment variables. An attacker who can invoke system.run with…

  • CVE-2021-3707MedAug 16, 2021
    risk 0.36cvss 5.5epss 0.02

    D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on the vulnerable device.

  • CVE-2026-4039MedMar 12, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. Upgrading to…

  • CVE-2025-43792MedSep 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly obtain the remote address of the…

  • CVE-2023-46764MedNov 8, 2023
    risk 0.34cvss 5.3epss 0.00

    Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously.

  • CVE-2026-56567MedJul 31, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

  • CVE-2026-22177MedMar 18, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution. Attackers can inject variables like NODE_OPTIONS or LD_* through configuration to execute arbitrary code in the…

  • CVE-2026-0495MedJan 13, 2026
    risk 0.33cvss 5.1epss 0.00

    SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.

  • CVE-2026-0232MedApr 13, 2026
    risk 0.29cvss 4.4epss 0.00

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

  • CVE-2023-32076MedMay 10, 2023
    risk 0.29cvss 5.5epss 0.00

    in-toto is a framework to protect supply chain integrity. The in-toto configuration is read from various directories and allows users to configure the behavior of the framework. The files are from directories following the XDG base directory specification. In versions 1.4.0 and…

  • CVE-2026-0418MedJun 9, 2026
    risk 0.28cvss —epss 0.00

    Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

  • CVE-2025-13091MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the shopire_admin_install_plugin() function in all versions up to, and including, 1.0.57. This makes it possible for authenticated attackers, with…