CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,970)
page 23 of 199| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36103 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request. | ||
| CVE-2024-44410 | Cri | 0.64 | 9.8 | 0.03 | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. | ||
| CVE-2024-44402 | Cri | 0.64 | 9.8 | 0.03 | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm. | ||
| CVE-2024-44401 | Cri | 0.64 | 9.8 | 0.03 | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file | ||
| CVE-2024-8073 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2024 | Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13. | ||
| CVE-2024-44382 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2024 | D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function. | ||
| CVE-2024-44381 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2024 | D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function. | ||
| CVE-2024-42947 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2024 | An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request. | ||
| CVE-2024-5914 | Cri | 0.64 | 9.8 | 0.01 | Aug 14, 2024 | A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | ||
| CVE-2024-21878 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and… | ||
| CVE-2024-41319 | Cri | 0.64 | 9.8 | 0.06 | Jul 23, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function. | ||
| CVE-2024-41318 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function. | ||
| CVE-2024-41316 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function. | ||
| CVE-2024-40110 | Cri | 0.64 | 9.8 | 0.02 | Jul 12, 2024 | Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php. | ||
| CVE-2024-39028 | Cri | 0.64 | 9.8 | 0.01 | Jul 5, 2024 | An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php. | ||
| CVE-2024-37091 | Cri | 0.64 | 9.9 | 0.01 | Jun 24, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a… | ||
| CVE-2024-36604 | Cri | 0.64 | 9.8 | 0.02 | Jun 4, 2024 | Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges. | ||
| CVE-2024-36783 | Cri | 0.64 | 9.8 | 0.01 | Jun 3, 2024 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function. | ||
| CVE-2024-4267 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2024 | A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' function. An attacker… | ||
| CVE-2024-32353 | Cri | 0.64 | 9.8 | 0.02 | May 14, 2024 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi. |
- risk 0.64cvss 9.8epss 0.01
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
- risk 0.64cvss 9.8epss 0.01
Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13.
- risk 0.64cvss 9.8epss 0.01
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.
- risk 0.64cvss 9.8epss 0.01
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.
- risk 0.64cvss 9.8epss 0.01
An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.01
A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and…
- risk 0.64cvss 9.8epss 0.06
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
- risk 0.64cvss 9.9epss 0.01
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a…
- risk 0.64cvss 9.8epss 0.02
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.
- risk 0.64cvss 9.8epss 0.01
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' function. An attacker…
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.