CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 128 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-48747 | Med | 0.44 | 6.8 | 0.01 | Nov 21, 2024 | An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file. | ||
| CVE-2024-38817 | Med | 0.44 | 6.7 | 0.01 | Oct 9, 2024 | VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root. | ||
| CVE-2024-44383 | Med | 0.44 | 6.8 | 0.01 | Sep 4, 2024 | WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm. | ||
| CVE-2023-26315 | Med | 0.44 | 6.5 | 0.19 | Aug 26, 2024 | The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device. | ||
| CVE-2024-41136 | Med | 0.44 | 6.8 | 0.01 | Jul 24, 2024 | An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying… | ||
| CVE-2023-40146 | Med | 0.44 | 6.8 | 0.01 | Apr 17, 2024 | A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials… | ||
| CVE-2024-0817 | Hig | 0.44 | 7.8 | 0.01 | Mar 7, 2024 | Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0 | ||
| CVE-2023-24046 | Med | 0.44 | 6.8 | 0.01 | Dec 4, 2023 | An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping utility. | ||
| CVE-2023-26319 | Med | 0.44 | 6.7 | 0.01 | Oct 11, 2023 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. | ||
| CVE-2023-36642 | Med | 0.44 | 6.7 | 0.00 | Sep 13, 2023 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing… | ||
| CVE-2023-25649 | Med | 0.44 | 6.8 | 0.02 | Aug 25, 2023 | There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands. | ||
| CVE-2023-4212 | Med | 0.44 | 6.8 | 0.01 | Aug 22, 2023 | A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick. | ||
| CVE-2023-40293 | Med | 0.44 | 6.8 | 0.02 | Aug 14, 2023 | Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object. | ||
| CVE-2022-43623 | Med | 0.44 | 6.8 | 0.01 | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw… | ||
| CVE-2022-45095 | Med | 0.44 | 6.7 | 0.01 | Feb 1, 2023 | Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of… | ||
| CVE-2022-39088 | Med | 0.44 | 6.7 | 0.00 | Jan 4, 2023 | In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. | ||
| CVE-2022-39087 | Med | 0.44 | 6.7 | 0.00 | Jan 4, 2023 | In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. | ||
| CVE-2022-39086 | Med | 0.44 | 6.7 | 0.00 | Jan 4, 2023 | In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. | ||
| CVE-2022-39085 | Med | 0.44 | 6.7 | 0.00 | Jan 4, 2023 | In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. | ||
| CVE-2022-39084 | Med | 0.44 | 6.7 | 0.00 | Jan 4, 2023 | In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
- risk 0.44cvss 6.8epss 0.01
An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.
- risk 0.44cvss 6.7epss 0.01
VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
- risk 0.44cvss 6.8epss 0.01
WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
- risk 0.44cvss 6.5epss 0.19
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
- risk 0.44cvss 6.8epss 0.01
An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying…
- risk 0.44cvss 6.8epss 0.01
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials…
- risk 0.44cvss 7.8epss 0.01
Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0
- risk 0.44cvss 6.8epss 0.01
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping utility.
- risk 0.44cvss 6.7epss 0.01
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
- risk 0.44cvss 6.7epss 0.00
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing…
- risk 0.44cvss 6.8epss 0.02
There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
- risk 0.44cvss 6.8epss 0.01
A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.
- risk 0.44cvss 6.8epss 0.02
Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.
- risk 0.44cvss 6.8epss 0.01
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw…
- risk 0.44cvss 6.7epss 0.01
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of…
- risk 0.44cvss 6.7epss 0.00
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- risk 0.44cvss 6.7epss 0.00
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- risk 0.44cvss 6.7epss 0.00
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- risk 0.44cvss 6.7epss 0.00
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- risk 0.44cvss 6.7epss 0.00
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.