VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 166 of 191
  • CVE-2025-5139MedMay 25, 2025
    risk 0.37cvss 5.6epss 0.03

    A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /html/ad/adconexaooffice365/request/testaConexaoOffice365.php of the component Office 365-type Connection Handler. The manipulation of…

  • CVE-2023-39523MedAug 7, 2023
    risk 0.37cvss 6.8epss 0.03

    ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a possible command injection vulnerability in the docker fetch process as it allows to append malicious commands in the…

  • CVE-2023-1708MedApr 5, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

  • CVE-2023-28110MedMar 16, 2023
    risk 0.37cvss 5.7epss 0.01

    Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to a Kubernetes cluster through Koko can…

  • CVE-2022-0764MedFeb 26, 2022
    risk 0.37cvss 6.7epss 0.01

    Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

  • CVE-2021-32661MedJun 3, 2021
    risk 0.37cvss 6.8epss 0.01

    Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within…

  • CVE-2021-32660MedJun 3, 2021
    risk 0.37cvss 6.8epss 0.01

    Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to upload documentation content with…

  • CVE-2019-17101MedApr 23, 2020
    risk 0.37cvss 5.7epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions prior to x.xx of Netatmo Smart Indoor Camera allows an attacker to execute commands on the device. This issue affects: Netatmo Smart Indoor Camera version and…

  • CVE-2017-12339MedNov 30, 2017
    risk 0.37cvss 5.7epss 0.01

    A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this…

  • CVE-2026-12223MedJun 15, 2026
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command…

  • CVE-2026-7608MedMay 2, 2026
    risk 0.36cvss 5.5epss 0.05

    A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injection. The exploit is now public and may be used. The vendor explains: "That firmware version will only work on…

  • CVE-2026-5679MedApr 6, 2026
    risk 0.36cvss 5.5epss 0.02

    A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. The exploit has been disclosed…

  • CVE-2026-20675MedFeb 11, 2026
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may…

  • CVE-2025-60689MedNov 13, 2025
    risk 0.36cvss 5.4epss 0.08

    An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip,…

  • CVE-2025-10961MedSep 25, 2025
    risk 0.36cvss 5.5epss 0.08

    A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-bin/wireless.cgi of the component Delete_Mac_list Page. Executing manipulation of the argument delete_list can lead to command injection. The vendor was…

  • CVE-2025-57733MedAug 20, 2025
    risk 0.36cvss 5.5epss 0.00

    In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content

  • CVE-2025-52377MedJul 15, 2025
    risk 0.36cvss 5.4epss 0.09

    Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authenticated attackers to execute arbitrary commands on the device. The vulnerability is present in the web management interface's ping and traceroute functionality,…

  • CVE-2025-51650MedJul 14, 2025
    risk 0.36cvss 5.6epss 0.00

    An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.

  • CVE-2025-6897MedJun 30, 2025
    risk 0.36cvss 5.5epss 0.03

    A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the file httpd_debug.asp. The manipulation of the argument Time leads to os command injection. The exploit has been disclosed to the…

  • CVE-2025-22476MedMay 6, 2025
    risk 0.36cvss 5.5epss 0.01

    Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability,…