VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 173 of 191
  • CVE-2025-25802MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

  • CVE-2025-25797MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.

  • CVE-2025-25796MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.

  • CVE-2025-25794MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.

  • CVE-2025-25793MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.

  • CVE-2024-57212MedJan 10, 2025
    risk 0.33cvss 5.1epss 0.01

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.

  • CVE-2024-11659MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.28

    A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_iperf. The manipulation of the argument iperf leads to command injection. The…

  • CVE-2024-11658MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.28

    A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChannelList. The manipulation of the argument countryCode leads…

  • CVE-2024-11657MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.28

    A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the file /admin/network/diag_nslookup. The manipulation of the argument diag_nslookup leads to command injection. It is…

  • CVE-2024-11656MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.27

    A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The manipulation of the argument diag_ping6 leads to command…

  • CVE-2024-11655MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.27

    A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of the argument diag_ping leads to command injection. The…

  • CVE-2024-11654MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.28

    A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argument diag_traceroute6 leads to command injection. It is…

  • CVE-2024-11653MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.28

    A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_traceroute. The manipulation of the argument diag_traceroute leads to…

  • CVE-2024-11652MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.29

    A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sn_package/sn_https. The manipulation of the argument https_enable leads to…

  • CVE-2024-11651MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.26

    A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of the file /admin/network/wifi_schedule. The manipulation of the argument wifi_schedule_day_em_5 leads to command…

  • CVE-2021-38120MedAug 28, 2024
    risk 0.33cvss 5.1epss 0.01

    A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.

  • CVE-2024-28135MedMay 14, 2024
    risk 0.33cvss 5.0epss 0.01

    A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.

  • CVE-2018-19013MedJan 22, 2019
    risk 0.33cvss 5.0epss 0.01

    An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file.

  • CVE-2026-3798MedMar 9, 2026
    risk 0.32cvss 4.7epss 0.15

    A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component Request Path Handler. The manipulation results in command injection. The attack may be launched…

  • CVE-2026-3662MedMar 7, 2026
    risk 0.32cvss 4.7epss 0.18

    A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such manipulation of the argument Pr_mode leads to command injection. It is possible to launch the attack remotely. The exploit has been…