VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 20 of 191
  • CVE-2025-25675CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function,…

  • CVE-2025-22630CriFeb 14, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widget Options widget-options allows OS Command Injection.This issue affects Widget Options: from n/a through <= 4.1.0.

  • CVE-2024-55062CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.

  • CVE-2024-57590CriJan 27, 2025
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.

  • CVE-2024-57583CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.

  • CVE-2025-22912CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.

  • CVE-2024-57225CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

  • CVE-2024-57224CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

  • CVE-2024-57223CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

  • CVE-2025-22949CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.

  • CVE-2024-55414CriJan 7, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges,…

  • CVE-2022-32203CriDec 20, 2024
    risk 0.64cvss 9.8epss 0.01

    There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the printer. (Vulnerability ID: HWPSIRT-2022-51773) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE)…

  • CVE-2024-55461CriDec 18, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().

  • CVE-2024-50388CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.02

    An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673…

  • CVE-2024-37782CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.

  • CVE-2024-48860CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and later

  • CVE-2024-28729CriNov 12, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted request.

  • CVE-2024-25255CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior.

  • CVE-2024-51115CriNov 5, 2024
    risk 0.64cvss 9.8epss 0.02

    DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.

  • CVE-2024-48746CriNov 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component