VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 178 of 191
  • CVE-2023-38690MedAug 4, 2023
    risk 0.31cvss 5.8epss 0.01

    matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge…

  • CVE-2023-0849MedFeb 15, 2023
    risk 0.31cvss 4.7epss 0.03

    A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to…

  • CVE-2022-20801MedMay 4, 2022
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities…

  • CVE-2022-20799MedMay 4, 2022
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities…

  • CVE-2020-26300MedSep 9, 2021
    risk 0.31cvss 5.9epss 0.01

    systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix.

  • CVE-2021-33515MedJun 28, 2021
    risk 0.31cvss 4.8epss 0.03

    The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

  • CVE-2021-1555MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1554MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1553MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1552MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1551MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1550MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1549MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1548MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1547MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2017-6184MedMar 30, 2017
    risk 0.31cvss 4.7epss 0.03

    In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.

  • CVE-2025-9262MedAug 20, 2025
    risk 0.30cvss 5.6epss 0.05

    A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handler. This manipulation causes os command injection. The attack may be initiated remotely. The attack is considered to…

  • CVE-2025-1369MedFeb 17, 2025
    risk 0.30cvss 4.5epss 0.03

    A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerability is an unknown functionality of the component USB Password Handler. The manipulation leads to os command injection. The attack needs to be approached…

  • CVE-2023-20097MedMar 23, 2023
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to…

  • CVE-2026-19266MedAug 8, 2026
    risk 0.29cvss 5.5epss 0.02

    A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading…