VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 109 of 192
  • CVE-2020-28433HigAug 2, 2022
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package node-latex-pdf.

  • CVE-2020-28425HigAug 2, 2022
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package curljs.

  • CVE-2020-28436HigJul 25, 2022
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package google-cloudstorage-commands.

  • CVE-2022-2054HigJun 12, 2022
    risk 0.48cvss 8.4epss 0.01

    Code Injection in GitHub repository nuitka/nuitka prior to 0.9.

  • CVE-2021-23381HigApr 18, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2021-23379HigApr 18, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2021-23375HigApr 18, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2021-23374HigApr 18, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2020-28426HigFeb 1, 2021
    risk 0.48cvss 7.3epss 0.02

    All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.

  • CVE-2020-26929HigOct 9, 2020
    risk 0.48cvss 7.3epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.

  • CVE-2018-19015HigJan 28, 2019
    risk 0.48cvss 7.3epss 0.01

    An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application.

  • CVE-2017-15403HigJan 9, 2019
    risk 0.48cvss 7.3epss 0.01

    Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2011-4182HigJun 12, 2018
    risk 0.48cvss 7.3epss 0.02

    Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.

  • CVE-2017-12094HigNov 7, 2017
    risk 0.48cvss 7.4epss 0.01

    An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the device to trigger this…

  • CVE-2026-19771HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.03

    A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be…

  • CVE-2026-47299HigAug 11, 2026
    risk 0.47cvss 7.2epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-19036HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.02

    A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released…

  • CVE-2026-19035HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit…

  • CVE-2026-19034HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched…

  • CVE-2026-7693HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.02

    The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context…