CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,816)
page 27 of 191| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39638 | Cri | 0.64 | 9.8 | 0.03 | Sep 14, 2023 | D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin. | ||
| CVE-2023-41011 | Cri | 0.64 | 9.8 | 0.02 | Sep 14, 2023 | Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component. | ||
| CVE-2023-39637 | Cri | 0.64 | 9.8 | 0.02 | Sep 12, 2023 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis. | ||
| CVE-2023-4310 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote… | ||
| CVE-2023-38027 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service. | ||
| CVE-2023-39834 | Cri | 0.64 | 9.8 | 0.02 | Aug 24, 2023 | PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function. | ||
| CVE-2023-39618 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface. | ||
| CVE-2023-39617 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. | ||
| CVE-2023-39809 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php. | ||
| CVE-2023-38866 | Cri | 0.64 | 9.8 | 0.02 | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name. | ||
| CVE-2023-38864 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt. | ||
| CVE-2023-38865 | Cri | 0.64 | 9.8 | 0.02 | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr. | ||
| CVE-2023-38863 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt. | ||
| CVE-2023-38862 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt. | ||
| CVE-2023-38861 | Cri | 0.64 | 9.8 | 0.02 | Aug 15, 2023 | An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi. | ||
| CVE-2023-39293 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2023 | A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system. | ||
| CVE-2023-38034 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches… | ||
| CVE-2023-38928 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi. | ||
| CVE-2023-38941 | Cri | 0.64 | 9.8 | 0.02 | Aug 4, 2023 | django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post. | ||
| CVE-2023-38942 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2023 | Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json. |
- risk 0.64cvss 9.8epss 0.03
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.
- risk 0.64cvss 9.8epss 0.02
Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
- risk 0.64cvss 9.8epss 0.01
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote…
- risk 0.64cvss 9.8epss 0.01
SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service.
- risk 0.64cvss 9.8epss 0.02
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
- risk 0.64cvss 9.8epss 0.01
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.
- risk 0.64cvss 9.8epss 0.02
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name.
- risk 0.64cvss 9.8epss 0.01
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.
- risk 0.64cvss 9.8epss 0.02
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.
- risk 0.64cvss 9.8epss 0.01
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt.
- risk 0.64cvss 9.8epss 0.01
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt.
- risk 0.64cvss 9.8epss 0.02
An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.
- risk 0.64cvss 9.8epss 0.02
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
- risk 0.64cvss 9.8epss 0.01
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches…
- risk 0.64cvss 9.8epss 0.01
Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.
- risk 0.64cvss 9.8epss 0.02
django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post.
- risk 0.64cvss 9.8epss 0.02
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.