VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 107 of 192
  • CVE-2025-23094HigFeb 6, 2025
    risk 0.48cvss 7.3epss 0.01

    The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter…

  • CVE-2025-0328HigJan 9, 2025
    risk 0.48cvss 7.3epss 0.02

    A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality of the file /public/server/runCode.php of the component HTTP POST Request Handler. The manipulation of the argument…

  • CVE-2024-49194HigDec 17, 2024
    risk 0.48cvss 7.3epss 0.01

    Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could potentially exploit this…

  • CVE-2024-10429HigOct 27, 2024
    risk 0.48cvss 7.2epss 0.18

    A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the argument IPv6OpMode/IPv6IPAddr/IPv6WANIPAddr/IPv6GWAddr leads to command injection.…

  • CVE-2024-10428HigOct 27, 2024
    risk 0.48cvss 7.2epss 0.15

    A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be…

  • CVE-2024-39563HigOct 11, 2024
    risk 0.48cvss 7.3epss 0.01

    A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the web…

  • CVE-2023-37154HigOct 9, 2024
    risk 0.48cvss 8.4epss 0.00

    check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

  • CVE-2024-43497HigOct 8, 2024
    risk 0.48cvss 8.4epss 0.01

    DeepSpeed Remote Code Execution Vulnerability

  • CVE-2024-8640HigSep 12, 2024
    risk 0.48cvss 8.5epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.

  • CVE-2024-33508HigSep 10, 2024
    risk 0.48cvss 7.3epss 0.01

    An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying…

  • CVE-2023-47563HigSep 6, 2024
    risk 0.48cvss 7.4epss 0.01

    An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later

  • CVE-2024-28739HigAug 6, 2024
    risk 0.48cvss 7.2epss 0.19

    An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

  • CVE-2024-6257HigJun 25, 2024
    risk 0.48cvss 8.4epss 0.01

    HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

  • CVE-2024-32283HigApr 17, 2024
    risk 0.48cvss 7.3epss 0.01

    Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter.

  • CVE-2024-22246HigApr 2, 2024
    risk 0.48cvss 7.4epss 0.00

    VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full…

  • CVE-2024-2947HigMar 28, 2024
    risk 0.48cvss 7.3epss 0.01

    A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

  • CVE-2024-2642HigMar 19, 2024
    risk 0.48cvss 7.3epss 0.03

    A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /EXCU_SHELL. The manipulation of the argument Command1 leads to command injection. The attack can be…

  • CVE-2023-41334HigMar 18, 2024
    risk 0.48cvss 8.4epss 0.01

    Astropy is a project for astronomy in Python that fosters interoperability between Python astronomy packages. Version 5.3.2 of the Astropy core package is vulnerable to remote code execution due to improper input validation in the `TranformGraph().to_dot_graph` function. A…

  • CVE-2024-25998HigMar 12, 2024
    risk 0.48cvss 7.3epss 0.01

    An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.

  • CVE-2023-47218MedFeb 13, 2024
    risk 0.48cvss 5.8epss 0.90

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build…