VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,834)

page 28 of 192
  • CVE-2023-38942CriAug 3, 2023
    risk 0.64cvss 9.8epss 0.02

    Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.

  • CVE-2023-37214CriJul 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.

  • CVE-2023-37794CriJul 14, 2023
    risk 0.64cvss 9.8epss 0.02

    WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.

  • CVE-2023-38336CriJul 14, 2023
    risk 0.64cvss 9.8epss 0.02

    netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.

  • CVE-2023-37567CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.02

    Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows:…

  • CVE-2023-37149CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.

  • CVE-2023-37148CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.

  • CVE-2023-37146CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

  • CVE-2023-37145CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.

  • CVE-2023-37144CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

  • CVE-2023-34849CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.03

    An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.

  • CVE-2023-31746CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.

  • CVE-2023-27836CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.

  • CVE-2023-27837CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 40A774.

  • CVE-2023-26295CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.02

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2023-33556CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.

  • CVE-2023-30400CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within the MCU's operating system allows attackers to perform arbitrary command execution via a crafted wifi SSID or password.

  • CVE-2023-31569CriJun 6, 2023
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.

  • CVE-2023-23952CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.

  • CVE-2023-33487CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.