CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 114 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-53700 | Hig | 0.47 | 7.2 | 0.01 | Mar 7, 2025 | A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter… | ||
| CVE-2025-22962 | Hig | 0.47 | 7.2 | 0.01 | Feb 13, 2025 | A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when debugging mode is enabled. An attacker with a valid session ID (sess_id) can send specially crafted POST requests to the /json… | ||
| CVE-2025-25743 | Hig | 0.47 | 7.2 | 0.02 | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings module. | ||
| CVE-2025-0528 | Hig | 0.47 | 7.2 | 0.06 | Jan 17, 2025 | A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The… | ||
| CVE-2025-23052 | Hig | 0.47 | 7.2 | 0.01 | Jan 14, 2025 | Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | ||
| CVE-2024-54007 | Hig | 0.47 | 7.2 | 0.02 | Jan 7, 2025 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands… | ||
| CVE-2024-54006 | Hig | 0.47 | 7.2 | 0.02 | Jan 7, 2025 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands… | ||
| CVE-2024-13062 | Hig | 0.47 | 7.2 | 0.01 | Jan 2, 2025 | An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. | ||
| CVE-2024-12912 | Hig | 0.47 | 7.2 | 0.01 | Jan 2, 2025 | An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. | ||
| CVE-2024-51771 | Hig | 0.47 | 7.2 | 0.01 | Dec 3, 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the… | ||
| CVE-2024-11013 | Hig | 0.47 | 7.2 | 0.01 | Nov 29, 2024 | Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device… | ||
| CVE-2021-27702 | Hig | 0.47 | 7.3 | 0.00 | Nov 12, 2024 | Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard. | ||
| CVE-2024-49042 | Hig | 0.47 | 7.2 | 0.01 | Nov 12, 2024 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | ||
| CVE-2024-43613 | Hig | 0.47 | 7.2 | 0.01 | Nov 12, 2024 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | ||
| CVE-2024-50572 | Hig | 0.47 | 7.2 | 0.01 | Nov 12, 2024 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.2), SCALANCE M812-1 ADSL-Router… | ||
| CVE-2024-47461 | Hig | 0.47 | 7.2 | 0.02 | Nov 5, 2024 | An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This… | ||
| CVE-2024-41153 | Hig | 0.47 | 7.2 | 0.02 | Oct 29, 2024 | Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive… | ||
| CVE-2024-6333 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2024 | Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products. | ||
| CVE-2024-38228 | Hig | 0.47 | 7.2 | 0.04 | Sep 10, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-38227 | Hig | 0.47 | 7.2 | 0.08 | Sep 10, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
- risk 0.47cvss 7.2epss 0.01
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter…
- risk 0.47cvss 7.2epss 0.01
A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when debugging mode is enabled. An attacker with a valid session ID (sess_id) can send specially crafted POST requests to the /json…
- risk 0.47cvss 7.2epss 0.02
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings module.
- risk 0.47cvss 7.2epss 0.06
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The…
- risk 0.47cvss 7.2epss 0.01
Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
- risk 0.47cvss 7.2epss 0.02
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands…
- risk 0.47cvss 7.2epss 0.02
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands…
- risk 0.47cvss 7.2epss 0.01
An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
- risk 0.47cvss 7.2epss 0.01
An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
- risk 0.47cvss 7.2epss 0.01
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the…
- risk 0.47cvss 7.2epss 0.01
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device…
- risk 0.47cvss 7.3epss 0.00
Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.
- risk 0.47cvss 7.2epss 0.01
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
- risk 0.47cvss 7.2epss 0.01
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
- risk 0.47cvss 7.2epss 0.01
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.2), SCALANCE M812-1 ADSL-Router…
- risk 0.47cvss 7.2epss 0.02
An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This…
- risk 0.47cvss 7.2epss 0.02
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive…
- risk 0.47cvss 7.2epss 0.01
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
- risk 0.47cvss 7.2epss 0.04
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.08
Microsoft SharePoint Server Remote Code Execution Vulnerability