CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,834)
page 28 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38942 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2023 | Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json. | ||
| CVE-2023-37214 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2023 | Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025. | ||
| CVE-2023-37794 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2023 | WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp. | ||
| CVE-2023-38336 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2023 | netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778. | ||
| CVE-2023-37567 | Cri | 0.64 | 9.8 | 0.02 | Jul 13, 2023 | Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows:… | ||
| CVE-2023-37149 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function. | ||
| CVE-2023-37148 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function. | ||
| CVE-2023-37146 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. | ||
| CVE-2023-37145 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. | ||
| CVE-2023-37144 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac. | ||
| CVE-2023-34849 | Cri | 0.64 | 9.8 | 0.03 | Jun 29, 2023 | An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1. | ||
| CVE-2023-31746 | Cri | 0.64 | 9.8 | 0.03 | Jun 14, 2023 | There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user. | ||
| CVE-2023-27836 | Cri | 0.64 | 9.8 | 0.02 | Jun 13, 2023 | TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C. | ||
| CVE-2023-27837 | Cri | 0.64 | 9.8 | 0.02 | Jun 13, 2023 | TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 40A774. | ||
| CVE-2023-26295 | Cri | 0.64 | 9.8 | 0.02 | Jun 12, 2023 | Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges. | ||
| CVE-2023-33556 | Cri | 0.64 | 9.8 | 0.02 | Jun 7, 2023 | TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg. | ||
| CVE-2023-30400 | Cri | 0.64 | 9.8 | 0.03 | Jun 7, 2023 | An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within the MCU's operating system allows attackers to perform arbitrary command execution via a crafted wifi SSID or password. | ||
| CVE-2023-31569 | Cri | 0.64 | 9.8 | 0.03 | Jun 6, 2023 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function. | ||
| CVE-2023-23952 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2023 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability. | ||
| CVE-2023-33487 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter. |
- risk 0.64cvss 9.8epss 0.02
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.
- risk 0.64cvss 9.8epss 0.01
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
- risk 0.64cvss 9.8epss 0.02
WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.
- risk 0.64cvss 9.8epss 0.02
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.
- risk 0.64cvss 9.8epss 0.02
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows:…
- risk 0.64cvss 9.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
- risk 0.64cvss 9.8epss 0.03
An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.
- risk 0.64cvss 9.8epss 0.03
There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.
- risk 0.64cvss 9.8epss 0.02
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.
- risk 0.64cvss 9.8epss 0.02
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 40A774.
- risk 0.64cvss 9.8epss 0.02
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
- risk 0.64cvss 9.8epss 0.02
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within the MCU's operating system allows attackers to perform arbitrary command execution via a crafted wifi SSID or password.
- risk 0.64cvss 9.8epss 0.03
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
- risk 0.64cvss 9.8epss 0.01
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.