CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 109 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-28433 | Hig | 0.48 | 7.3 | 0.01 | Aug 2, 2022 | This affects all versions of package node-latex-pdf. | ||
| CVE-2020-28425 | Hig | 0.48 | 7.3 | 0.01 | Aug 2, 2022 | This affects all versions of package curljs. | ||
| CVE-2020-28436 | Hig | 0.48 | 7.3 | 0.01 | Jul 25, 2022 | This affects all versions of package google-cloudstorage-commands. | ||
| CVE-2022-2054 | Hig | 0.48 | 8.4 | 0.01 | Jun 12, 2022 | Code Injection in GitHub repository nuitka/nuitka prior to 0.9. | ||
| CVE-2021-23381 | Hig | 0.48 | 7.3 | 0.01 | Apr 18, 2021 | This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | ||
| CVE-2021-23379 | Hig | 0.48 | 7.3 | 0.01 | Apr 18, 2021 | This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | ||
| CVE-2021-23375 | Hig | 0.48 | 7.3 | 0.01 | Apr 18, 2021 | This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | ||
| CVE-2021-23374 | Hig | 0.48 | 7.3 | 0.01 | Apr 18, 2021 | This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | ||
| CVE-2020-28426 | Hig | 0.48 | 7.3 | 0.02 | Feb 1, 2021 | All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId. | ||
| CVE-2020-26929 | Hig | 0.48 | 7.3 | 0.01 | Oct 9, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100. | ||
| CVE-2018-19015 | Hig | 0.48 | 7.3 | 0.01 | Jan 28, 2019 | An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application. | ||
| CVE-2017-15403 | Hig | 0.48 | 7.3 | 0.01 | Jan 9, 2019 | Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page. | ||
| CVE-2011-4182 | Hig | 0.48 | 7.3 | 0.02 | Jun 12, 2018 | Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1. | ||
| CVE-2017-12094 | Hig | 0.48 | 7.4 | 0.01 | Nov 7, 2017 | An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the device to trigger this… | ||
| CVE-2026-19771 | Hig | 0.47 | 7.2 | 0.03 | Aug 14, 2026 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be… | ||
| CVE-2026-47299 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-19036 | Hig | 0.47 | 7.2 | 0.02 | Aug 6, 2026 | A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released… | ||
| CVE-2026-19035 | Hig | 0.47 | 7.2 | 0.02 | Aug 6, 2026 | A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit… | ||
| CVE-2026-19034 | Hig | 0.47 | 7.2 | 0.02 | Aug 6, 2026 | A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched… | ||
| CVE-2026-7693 | Hig | 0.47 | 7.2 | 0.02 | Aug 5, 2026 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context… |
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package node-latex-pdf.
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package curljs.
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package google-cloudstorage-commands.
- risk 0.48cvss 8.4epss 0.01
Code Injection in GitHub repository nuitka/nuitka prior to 0.9.
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
- risk 0.48cvss 7.3epss 0.02
All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.
- risk 0.48cvss 7.3epss 0.01
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.
- risk 0.48cvss 7.3epss 0.01
An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application.
- risk 0.48cvss 7.3epss 0.01
Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.
- risk 0.48cvss 7.3epss 0.02
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.
- risk 0.48cvss 7.4epss 0.01
An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the device to trigger this…
- risk 0.47cvss 7.2epss 0.03
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be…
- risk 0.47cvss 7.2epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
- risk 0.47cvss 7.2epss 0.02
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released…
- risk 0.47cvss 7.2epss 0.02
A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit…
- risk 0.47cvss 7.2epss 0.02
A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched…
- risk 0.47cvss 7.2epss 0.02
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context…