VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 185 of 199
  • CVE-2024-9042MedMar 13, 2025
    risk 0.31cvss 5.9epss 0.01

    This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.

  • CVE-2024-53692MedMar 7, 2025
    risk 0.31cvss 4.7epss 0.01

    A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the…

  • CVE-2025-1616MedFeb 24, 2025
    risk 0.31cvss 4.7epss 0.08

    A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown functionality of the component Diagnosis. The manipulation of the argument Destination Address leads to os command injection. The…

  • CVE-2025-25766MedFeb 21, 2025
    risk 0.31cvss 4.8epss 0.00

    An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.

  • CVE-2024-53672MedDec 3, 2024
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the…

  • CVE-2024-8983MedOct 8, 2024
    risk 0.31cvss 4.8epss 0.00

    Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-29737MedJul 17, 2024
    risk 0.31cvss 4.7epss 0.01

    In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the…

  • CVE-2023-52291MedJul 17, 2024
    risk 0.31cvss 4.7epss 0.02

    In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the…

  • CVE-2024-5196MedMay 22, 2024
    risk 0.31cvss 4.7epss 0.23

    A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /tools_command.php. The manipulation of the argument cmb_header/txt_command leads to command injection. It is possible to initiate the attack remotely. The…

  • CVE-2024-5195MedMay 22, 2024
    risk 0.31cvss 4.7epss 0.23

    A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /diag_s.php. The manipulation of the argument customer_info leads to command injection. The attack may be launched remotely. The…

  • CVE-2024-5194MedMay 22, 2024
    risk 0.31cvss 4.7epss 0.04

    A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /assoc_table.php. The manipulation of the argument id leads to command injection. The attack can be launched remotely. The…

  • CVE-2023-43510MedOct 25, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a non-privileged user on the…

  • CVE-2023-38690MedAug 4, 2023
    risk 0.31cvss 5.8epss 0.01

    matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge…

  • CVE-2023-0849MedFeb 15, 2023
    risk 0.31cvss 4.7epss 0.03

    A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to…

  • CVE-2022-20801MedMay 4, 2022
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities…

  • CVE-2022-20799MedMay 4, 2022
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities…

  • CVE-2020-26300MedSep 9, 2021
    risk 0.31cvss 5.9epss 0.01

    systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix.

  • CVE-2021-33515MedJun 28, 2021
    risk 0.31cvss 4.8epss 0.03

    The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

  • CVE-2021-1555MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…

  • CVE-2021-1554MedMay 22, 2021
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are…