VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 137 of 192
  • CVE-2025-66715MedJan 9, 2026
    risk 0.42cvss 6.5epss 0.00

    A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.

  • CVE-2026-0732MedJan 9, 2026
    risk 0.42cvss 6.3epss 0.10

    A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exploit has been made public and could be…

  • CVE-2025-61489MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.01

    A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.

  • CVE-2026-0581MedJan 5, 2026
    risk 0.42cvss 6.3epss 0.09

    A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command…

  • CVE-2025-69256HigDec 30, 2025
    risk 0.42cvss 7.5epss 0.02

    The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Starting in version 4.29.0 and prior to version 4.29.3, a command injection vulnerability exists in the Serverless Framework's built-in MCP server package…

  • CVE-2025-15139MedDec 28, 2025
    risk 0.42cvss 6.3epss 0.12

    A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4  of the file /boafrm/formWsc. Such manipulation of the argument peerPin leads to command injection. The attack can be executed remotely. The exploit has been disclosed to…

  • CVE-2025-15133MedDec 28, 2025
    risk 0.42cvss 6.3epss 0.07

    A vulnerability was identified in ZSPACE Z4Pro+ 1.0.0440024. The impacted element is the function zfilev2_api_CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. Such manipulation leads to command injection. It is possible to launch the attack…

  • CVE-2025-45493MedDec 23, 2025
    risk 0.42cvss 6.5epss 0.01

    Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.

  • CVE-2025-67436MedDec 22, 2025
    risk 0.42cvss 6.5epss 0.01

    Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).

  • CVE-2025-55901MedDec 15, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.

  • CVE-2025-55893MedDec 15, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.

  • CVE-2025-14225MedDec 8, 2025
    risk 0.42cvss 6.3epss 0.09

    A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the argument AdminID can lead to command injection. The attack can be executed remotely. The exploit has been…

  • CVE-2025-57200MedDec 3, 2025
    risk 0.42cvss 6.5epss 0.02

    AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2025-65657MedDec 2, 2025
    risk 0.42cvss 6.5epss 0.00

    FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation,…

  • CVE-2025-13800MedDec 1, 2025
    risk 0.42cvss 6.3epss 0.10

    A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-13799MedDec 1, 2025
    risk 0.42cvss 6.3epss 0.10

    A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.cgi. The manipulation of the argument mac leads to command injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-37162MedNov 18, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

  • CVE-2025-63749MedNov 18, 2025
    risk 0.42cvss 6.5epss 0.01

    pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.

  • CVE-2025-63258MedNov 18, 2025
    risk 0.42cvss 6.5epss 0.00

    A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series routers, cloud gateways, and wireless access points (versions R0162P07, UAP700-WPT330-E2265, UAP672-WPT330-R2262, UAP662E-WPT330-R2262P03,…

  • CVE-2025-63604MedNov 18, 2025
    risk 0.42cvss 6.5epss 0.00

    A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input validation in the execute_query method. The vulnerability stems from the exposure of dangerous Python built-in functions…