VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 128 of 192
  • CVE-2024-48747MedNov 21, 2024
    risk 0.44cvss 6.8epss 0.01

    An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.

  • CVE-2024-38817MedOct 9, 2024
    risk 0.44cvss 6.7epss 0.01

    VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.

  • CVE-2024-44383MedSep 4, 2024
    risk 0.44cvss 6.8epss 0.01

    WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.

  • CVE-2023-26315MedAug 26, 2024
    risk 0.44cvss 6.5epss 0.19

    The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.

  • CVE-2024-41136MedJul 24, 2024
    risk 0.44cvss 6.8epss 0.01

    An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying…

  • CVE-2023-40146MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.01

    A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials…

  • CVE-2024-0817HigMar 7, 2024
    risk 0.44cvss 7.8epss 0.01

    Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

  • CVE-2023-24046MedDec 4, 2023
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping utility.

  • CVE-2023-26319MedOct 11, 2023
    risk 0.44cvss 6.7epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

  • CVE-2023-36642MedSep 13, 2023
    risk 0.44cvss 6.7epss 0.00

    An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing…

  • CVE-2023-25649MedAug 25, 2023
    risk 0.44cvss 6.8epss 0.02

    There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

  • CVE-2023-4212MedAug 22, 2023
    risk 0.44cvss 6.8epss 0.01

    ​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

  • CVE-2023-40293MedAug 14, 2023
    risk 0.44cvss 6.8epss 0.02

    Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.

  • CVE-2022-43623MedMar 29, 2023
    risk 0.44cvss 6.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw…

  • CVE-2022-45095MedFeb 1, 2023
    risk 0.44cvss 6.7epss 0.01

    Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading to execute arbitrary commands, denial of…

  • CVE-2022-39088MedJan 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2022-39087MedJan 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2022-39086MedJan 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2022-39085MedJan 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2022-39084MedJan 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.