VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 24 of 191
  • CVE-2023-51887CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.02

    Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.

  • CVE-2024-22663CriJan 23, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg

  • CVE-2023-52042CriJan 16, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.

  • CVE-2023-52027CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.

  • CVE-2023-51972CriJan 10, 2024
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.

  • CVE-2023-51812CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

  • CVE-2023-51016CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.

  • CVE-2023-51014CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi

  • CVE-2023-51025CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.

  • CVE-2023-51707CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected.

  • CVE-2023-50989CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.

  • CVE-2023-50983CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.

  • CVE-2023-50089CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.04

    A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.

  • CVE-2013-2513CriDec 12, 2023
    risk 0.64cvss 9.8epss 0.02

    The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.

  • CVE-2023-40301CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.

  • CVE-2023-49436CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

  • CVE-2023-49435CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX9 V22.03.01.46 is vulnerable to command injection.

  • CVE-2023-49431CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

  • CVE-2023-49437CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

  • CVE-2023-49428CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.03

    Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.