CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,816)
page 24 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-51887 | Cri | 0.64 | 9.8 | 0.02 | Jan 24, 2024 | Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL. | ||
| CVE-2024-22663 | Cri | 0.64 | 9.8 | 0.02 | Jan 23, 2024 | TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg | ||
| CVE-2023-52042 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2024 | An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter. | ||
| CVE-2023-52027 | Cri | 0.64 | 9.8 | 0.02 | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function. | ||
| CVE-2023-51972 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp. | ||
| CVE-2023-51812 | Cri | 0.64 | 9.8 | 0.01 | Jan 4, 2024 | Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList. | ||
| CVE-2023-51016 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2023 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi. | ||
| CVE-2023-51014 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2023 | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi | ||
| CVE-2023-51025 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2023 | TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi. | ||
| CVE-2023-51707 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2023 | MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected. | ||
| CVE-2023-50989 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function. | ||
| CVE-2023-50983 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function. | ||
| CVE-2023-50089 | Cri | 0.64 | 9.8 | 0.04 | Dec 15, 2023 | A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication. | ||
| CVE-2013-2513 | Cri | 0.64 | 9.8 | 0.02 | Dec 12, 2023 | The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file. | ||
| CVE-2023-40301 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. | ||
| CVE-2023-49436 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||
| CVE-2023-49435 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 is vulnerable to command injection. | ||
| CVE-2023-49431 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. | ||
| CVE-2023-49437 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||
| CVE-2023-49428 | Cri | 0.64 | 9.8 | 0.03 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. |
- risk 0.64cvss 9.8epss 0.02
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
- risk 0.64cvss 9.8epss 0.01
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.
- risk 0.64cvss 9.8epss 0.02
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
- risk 0.64cvss 9.8epss 0.01
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.01
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi
- risk 0.64cvss 9.8epss 0.01
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.
- risk 0.64cvss 9.8epss 0.01
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected.
- risk 0.64cvss 9.8epss 0.02
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
- risk 0.64cvss 9.8epss 0.02
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
- risk 0.64cvss 9.8epss 0.04
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
- risk 0.64cvss 9.8epss 0.02
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.
- risk 0.64cvss 9.8epss 0.01
NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- risk 0.64cvss 9.8epss 0.02
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.03
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.