VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 180 of 199
  • CVE-2025-64052MedDec 5, 2025
    risk 0.33cvss 5.1epss 0.03

    An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.

  • CVE-2025-60855MedOct 16, 2025
    risk 0.33cvss 5.1epss 0.00

    Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the…

  • CVE-2025-7578MedJul 14, 2025
    risk 0.33cvss 5.0epss 0.02

    A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been declared as critical. This vulnerability affects the function sendCommand of the file runcmd.sh. The manipulation of the argument cmd leads to command injection. The attack can be…

  • CVE-2025-5030MedMay 21, 2025
    risk 0.33cvss 5.0epss 0.02

    A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of the file internal/unpack/unpack.go of the component wxapkg File Parser. The manipulation leads to os command injection. The…

  • CVE-2025-4089MedApr 29, 2025
    risk 0.33cvss 5.1epss 0.00

    Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 138 and Thunderbird 138.

  • CVE-2025-4032MedApr 28, 2025
    risk 0.33cvss 5.0epss 0.03

    A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the function subprocess.run/subprocess.Popen of the file AWorld/aworld/virtual_environments/terminals/shell_tool.py. The manipulation…

  • CVE-2024-40070MedApr 16, 2025
    risk 0.33cvss 5.1epss 0.00

    Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2025-20117MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. …

  • CVE-2025-25813MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.

  • CVE-2025-25802MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

  • CVE-2025-25797MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.

  • CVE-2025-25796MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.

  • CVE-2025-25794MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.

  • CVE-2025-25793MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.

  • CVE-2024-57212MedJan 10, 2025
    risk 0.33cvss 5.1epss 0.01

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.

  • CVE-2024-11659MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.29

    A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_iperf. The manipulation of the argument iperf leads to command injection. The…

  • CVE-2024-11658MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.29

    A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChannelList. The manipulation of the argument countryCode leads…

  • CVE-2024-11657MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.29

    A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the file /admin/network/diag_nslookup. The manipulation of the argument diag_nslookup leads to command injection. It is…

  • CVE-2024-11656MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.29

    A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The manipulation of the argument diag_ping6 leads to command…

  • CVE-2024-11655MedNov 25, 2024
    risk 0.33cvss 4.7epss 0.29

    A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of the argument diag_ping leads to command injection. The…