CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,970)
page 25 of 199| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-7227 | Cri | 0.64 | 9.8 | 0.01 | Jan 25, 2024 | SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges. | ||
| CVE-2024-22529 | Cri | 0.64 | 9.8 | 0.02 | Jan 25, 2024 | TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa. | ||
| CVE-2023-52040 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function. | ||
| CVE-2023-52039 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function. | ||
| CVE-2023-52038 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2024 | An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function. | ||
| CVE-2023-51887 | Cri | 0.64 | 9.8 | 0.02 | Jan 24, 2024 | Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL. | ||
| CVE-2024-22663 | Cri | 0.64 | 9.8 | 0.02 | Jan 23, 2024 | TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg | ||
| CVE-2023-52042 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2024 | An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter. | ||
| CVE-2023-52027 | Cri | 0.64 | 9.8 | 0.02 | Jan 11, 2024 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function. | ||
| CVE-2023-51972 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp. | ||
| CVE-2023-51812 | Cri | 0.64 | 9.8 | 0.01 | Jan 4, 2024 | Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList. | ||
| CVE-2023-51016 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2023 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi. | ||
| CVE-2023-51014 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2023 | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi | ||
| CVE-2023-51025 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2023 | TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi. | ||
| CVE-2023-51707 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2023 | MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected. | ||
| CVE-2023-50989 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function. | ||
| CVE-2023-50983 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function. | ||
| CVE-2023-50089 | Cri | 0.64 | 9.8 | 0.04 | Dec 15, 2023 | A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication. | ||
| CVE-2013-2513 | Cri | 0.64 | 9.8 | 0.02 | Dec 12, 2023 | The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file. | ||
| CVE-2023-40301 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. |
- risk 0.64cvss 9.8epss 0.01
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
- risk 0.64cvss 9.8epss 0.02
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
- risk 0.64cvss 9.8epss 0.01
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.
- risk 0.64cvss 9.8epss 0.02
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
- risk 0.64cvss 9.8epss 0.01
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.01
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi
- risk 0.64cvss 9.8epss 0.01
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.
- risk 0.64cvss 9.8epss 0.01
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected.
- risk 0.64cvss 9.8epss 0.02
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
- risk 0.64cvss 9.8epss 0.02
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
- risk 0.64cvss 9.8epss 0.04
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
- risk 0.64cvss 9.8epss 0.02
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.
- risk 0.64cvss 9.8epss 0.01
NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.