VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 113 of 192
  • CVE-2025-64987HigDec 11, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands.…

  • CVE-2025-64986HigDec 11, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOnAPort instruction prior V21. Improper input validation, allowing authenticated attackers with Actioner privileges to inject…

  • CVE-2024-56837HigDec 9, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0),…

  • CVE-2025-65363HigDec 8, 2025
    risk 0.47cvss 7.2epss 0.07

    Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do…

  • CVE-2025-14188HigDec 7, 2025
    risk 0.47cvss 7.2epss 0.03

    A security vulnerability has been detected in UGREEN DH2100+ up to 5.3.0.251125. This impacts the function handler_file_backup_create of the file /v1/file/backup/create of the component nas_svr. The manipulation of the argument path leads to command injection. The attack is…

  • CVE-2025-37163HigNov 18, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying …

  • CVE-2025-37146HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2025-37134HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying…

  • CVE-2025-37133HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying…

  • CVE-2025-29887HigAug 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter…

  • CVE-2025-29523HigAug 25, 2025
    risk 0.47cvss 7.2epss 0.02

    D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function.

  • CVE-2025-29516HigAug 25, 2025
    risk 0.47cvss 7.2epss 0.02

    D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the backup function.

  • CVE-2025-50891HigAug 19, 2025
    risk 0.47cvss 7.2epss 0.00

    The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1).

  • CVE-2025-37102HigJul 8, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system…

  • CVE-2025-47959HigJun 13, 2025
    risk 0.47cvss 7.1epss 0.07

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.

  • CVE-2025-4231HigJun 13, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit this issue. Cloud…

  • CVE-2025-37091HigJun 2, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-43948HigApr 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.

  • CVE-2024-40445HigApr 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.

  • CVE-2025-27083HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on…