VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 169 of 191
  • CVE-2025-60671MedNov 13, 2025
    risk 0.35cvss 5.4epss 0.01

    A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /var/system/linux_vlan_reinit file. The vulnerability occurs because content read from this file is only…

  • CVE-2025-56769MedSep 25, 2025
    risk 0.35cvss 6.5epss 0.00

    An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the QLExpressEngine class.

  • CVE-2025-9528MedAug 27, 2025
    risk 0.35cvss 4.7epss 0.48

    A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit…

  • CVE-2025-29519MedAug 25, 2025
    risk 0.35cvss 5.3epss 0.02

    A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request.

  • CVE-2025-9176MedAug 20, 2025
    risk 0.35cvss 5.3epss 0.01

    A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Variable Handler. The manipulation results in os command injection. The attack is only possible with local access. The exploit has…

  • CVE-2025-9174MedAug 19, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filename Handler. Executing manipulation can lead to os command injection. The attack can only be executed locally. The exploit has…

  • CVE-2025-50817MedAug 14, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be…

  • CVE-2025-54393MedAug 7, 2025
    risk 0.35cvss 5.4epss 0.00

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.

  • CVE-2025-6522MedJun 27, 2025
    risk 0.35cvss 5.4epss 0.00

    Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on Port 16668. This vulnerability allows an attacker to run arbitrary commands on the Sight Bulb Pro by passing a well…

  • CVE-2025-20258MedMay 21, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails that are sent by the service. This vulnerability is due to insufficient input validation. An attacker could exploit this…

  • CVE-2025-26056MedApr 1, 2025
    risk 0.35cvss 5.4epss 0.01

    A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary…

  • CVE-2023-33300MedMar 14, 2025
    risk 0.35cvss 5.3epss 0.13

    A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication port.

  • CVE-2025-25768MedFeb 21, 2025
    risk 0.35cvss 5.4epss 0.00

    MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2025-1370MedFeb 17, 2025
    risk 0.35cvss 5.3epss 0.02

    A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the function sprintf of the file epsdaemon of the component Autoscan USB. The manipulation leads to os command injection. An attack has to…

  • CVE-2024-53526MedJan 8, 2025
    risk 0.35cvss 6.4epss 0.01

    composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.

  • CVE-2024-38896MedJun 24, 2024
    risk 0.35cvss 5.3epss 0.01

    WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.

  • CVE-2024-38894MedJun 24, 2024
    risk 0.35cvss 5.3epss 0.01

    WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

  • CVE-2024-34352MedMay 14, 2024
    risk 0.35cvss 6.5epss 0.01

    1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror…

  • CVE-2024-33113MedMay 6, 2024
    risk 0.35cvss 5.3epss 0.03

    D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

  • CVE-2024-32884MedApr 26, 2024
    risk 0.35cvss 6.4epss 0.01

    gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited,…