VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 143 of 192
  • CVE-2025-44848MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44845MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44844MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44843MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44842MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44841MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the version parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44840MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the svn parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44839MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the magicid parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-3987MedApr 27, 2025
    risk 0.42cvss 6.3epss 0.10

    A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The…

  • CVE-2025-28017MedApr 23, 2025
    risk 0.42cvss 6.5epss 0.01

    TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

  • CVE-2025-29743MedApr 22, 2025
    risk 0.42cvss 6.5epss 0.01

    D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

  • CVE-2024-48017MedMar 17, 2025
    risk 0.42cvss 6.5epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this…

  • CVE-2025-2094MedMar 7, 2025
    risk 0.42cvss 6.3epss 0.13

    A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliKey/key leads to os command injection. The…

  • CVE-2025-1829MedMar 2, 2025
    risk 0.42cvss 6.3epss 0.12

    A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknatCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mtkhnatEnable leads to os command injection. The attack can…

  • CVE-2024-57608MedFeb 24, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.

  • CVE-2025-1610MedFeb 24, 2025
    risk 0.42cvss 6.3epss 0.13

    A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the function websGetVar of the file /goform/set_blacklist. The manipulation of the argument mac/enable leads to os command injection. The attack may be launched…

  • CVE-2025-1609MedFeb 24, 2025
    risk 0.42cvss 6.3epss 0.10

    A vulnerability has been found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this vulnerability is the function websGetVar of the file /goform/set_cmd. The manipulation of the argument cmd leads to os command injection. The attack can be launched…

  • CVE-2025-1608MedFeb 24, 2025
    risk 0.42cvss 6.3epss 0.10

    A vulnerability, which was classified as critical, was found in LB-LINK AC1900 Router 1.0.2. Affected is the function websGetVar of the file /goform/set_manpwd. The manipulation of the argument routepwd  leads to os command injection. It is possible to launch the attack…

  • CVE-2025-25605MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.

  • CVE-2025-25604MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.