VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 27 of 199
  • CVE-2023-46422CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.

  • CVE-2023-46421CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.

  • CVE-2023-46420CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.

  • CVE-2023-46419CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.

  • CVE-2023-46418CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.

  • CVE-2023-46417CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.

  • CVE-2023-46416CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.

  • CVE-2023-46415CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.

  • CVE-2023-46414CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.

  • CVE-2023-46413CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.

  • CVE-2023-46412CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.

  • CVE-2023-46411CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.

  • CVE-2023-46410CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.

  • CVE-2023-46409CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.

  • CVE-2023-46408CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.

  • CVE-2023-36954CriOct 16, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.

  • CVE-2023-36953CriOct 16, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.

  • CVE-2023-45466CriOct 13, 2023
    risk 0.64cvss 9.8epss 0.02

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.

  • CVE-2023-45465CriOct 13, 2023
    risk 0.64cvss 9.8epss 0.02

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.

  • CVE-2023-43891CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.02

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.