CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,816)
page 26 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46417 | Cri | 0.64 | 9.8 | 0.02 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function. | ||
| CVE-2023-46416 | Cri | 0.64 | 9.8 | 0.02 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function. | ||
| CVE-2023-46415 | Cri | 0.64 | 9.8 | 0.02 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function. | ||
| CVE-2023-46414 | Cri | 0.64 | 9.8 | 0.02 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function. | ||
| CVE-2023-46413 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function. | ||
| CVE-2023-46412 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function. | ||
| CVE-2023-46411 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function. | ||
| CVE-2023-46410 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function. | ||
| CVE-2023-46409 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function. | ||
| CVE-2023-46408 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function. | ||
| CVE-2023-36954 | Cri | 0.64 | 9.8 | 0.02 | Oct 16, 2023 | TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection. | ||
| CVE-2023-36953 | Cri | 0.64 | 9.8 | 0.02 | Oct 16, 2023 | TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection. | ||
| CVE-2023-45466 | Cri | 0.64 | 9.8 | 0.02 | Oct 13, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings. | ||
| CVE-2023-45465 | Cri | 0.64 | 9.8 | 0.02 | Oct 13, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings. | ||
| CVE-2023-43891 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2023 | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload. | ||
| CVE-2023-43128 | Cri | 0.64 | 9.8 | 0.02 | Sep 21, 2023 | D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters. | ||
| CVE-2023-43207 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upload_handler. This vulnerability allows attackers to execute arbitrary commands via the configRestore parameter. | ||
| CVE-2023-43206 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_download_handler. This vulnerability allows attackers to execute arbitrary commands via the certDownload parameter. | ||
| CVE-2023-43204 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50. This vulnerability allows attackers to execute arbitrary commands via the manual-time-string parameter. | ||
| CVE-2023-43202 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2023 | D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerability allows attackers to execute arbitrary commands via the update.device.packet-capture.tftp-file-name parameter. |
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
- risk 0.64cvss 9.8epss 0.02
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.
- risk 0.64cvss 9.8epss 0.02
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.
- risk 0.64cvss 9.8epss 0.02
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.
- risk 0.64cvss 9.8epss 0.02
D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters.
- risk 0.64cvss 9.8epss 0.02
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upload_handler. This vulnerability allows attackers to execute arbitrary commands via the configRestore parameter.
- risk 0.64cvss 9.8epss 0.02
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_download_handler. This vulnerability allows attackers to execute arbitrary commands via the certDownload parameter.
- risk 0.64cvss 9.8epss 0.02
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50. This vulnerability allows attackers to execute arbitrary commands via the manual-time-string parameter.
- risk 0.64cvss 9.8epss 0.02
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerability allows attackers to execute arbitrary commands via the update.device.packet-capture.tftp-file-name parameter.