VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 17 of 199
  • CVE-2026-26792CriMar 12, 2026
    risk 0.64cvss 9.8epss 0.03

    GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. These vulnerabilities allow…

  • CVE-2026-26791CriMar 12, 2026
    risk 0.64cvss 9.8epss 0.02

    GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2026-3485CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.05

    A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.…

  • CVE-2026-3301CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.04

    A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os…

  • CVE-2026-2333CriFeb 20, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted network request.

  • CVE-2026-26093CriFeb 20, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted network request.

  • CVE-2026-2686CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. The manipulation of the argument User leads to os command injection. The attack is possible to be carried out remotely. The…

  • CVE-2026-22708CriJan 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an…

  • CVE-2025-15501CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.07

    A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote…

  • CVE-2025-15500CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.06

    A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results…

  • CVE-2025-69542CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.10

    A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper…

  • CVE-2025-29229CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

  • CVE-2025-29228CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

  • CVE-2025-50526CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

  • CVE-2025-66032CriDec 3, 2025
    risk 0.64cvss 9.8epss 0.01

    Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it was possible to bypass the Claude Code read-only validation and trigger arbitrary code execution. Reliably exploiting this requires the ability…

  • CVE-2025-60854CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.

  • CVE-2025-66219CriNov 29, 2025
    risk 0.64cvss 9.8epss 0.03

    willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which…

  • CVE-2025-58428CriOct 23, 2025
    risk 0.64cvss 9.9epss 0.01

    The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker…

  • CVE-2025-59741CriOct 2, 2025
    risk 0.64cvss 9.8epss 0.01

    Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in…

  • CVE-2025-59740CriOct 2, 2025
    risk 0.64cvss 9.8epss 0.01

    Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in…