CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,970)
page 29 of 199| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39293 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2023 | A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system. | ||
| CVE-2023-38034 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches… | ||
| CVE-2023-38928 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi. | ||
| CVE-2023-38941 | Cri | 0.64 | 9.8 | 0.02 | Aug 4, 2023 | django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post. | ||
| CVE-2023-38942 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2023 | Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json. | ||
| CVE-2023-37214 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2023 | Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025. | ||
| CVE-2023-37794 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2023 | WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp. | ||
| CVE-2023-38336 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2023 | netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778. | ||
| CVE-2023-37567 | Cri | 0.64 | 9.8 | 0.02 | Jul 13, 2023 | Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows:… | ||
| CVE-2023-37149 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function. | ||
| CVE-2023-37148 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function. | ||
| CVE-2023-37146 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. | ||
| CVE-2023-37145 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. | ||
| CVE-2023-37144 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2023 | Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac. | ||
| CVE-2023-34849 | Cri | 0.64 | 9.8 | 0.03 | Jun 29, 2023 | An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1. | ||
| CVE-2023-31746 | Cri | 0.64 | 9.8 | 0.03 | Jun 14, 2023 | There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user. | ||
| CVE-2023-27836 | Cri | 0.64 | 9.8 | 0.02 | Jun 13, 2023 | TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C. | ||
| CVE-2023-27837 | Cri | 0.64 | 9.8 | 0.02 | Jun 13, 2023 | TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 40A774. | ||
| CVE-2023-26295 | Cri | 0.64 | 9.8 | 0.02 | Jun 12, 2023 | Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges. | ||
| CVE-2023-33556 | Cri | 0.64 | 9.8 | 0.02 | Jun 7, 2023 | TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg. |
- risk 0.64cvss 9.8epss 0.02
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
- risk 0.64cvss 9.8epss 0.01
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches…
- risk 0.64cvss 9.8epss 0.01
Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.
- risk 0.64cvss 9.8epss 0.02
django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post.
- risk 0.64cvss 9.8epss 0.02
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.
- risk 0.64cvss 9.8epss 0.01
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
- risk 0.64cvss 9.8epss 0.02
WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.
- risk 0.64cvss 9.8epss 0.02
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.
- risk 0.64cvss 9.8epss 0.02
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows:…
- risk 0.64cvss 9.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
- risk 0.64cvss 9.8epss 0.03
An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.
- risk 0.64cvss 9.8epss 0.03
There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.
- risk 0.64cvss 9.8epss 0.02
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.
- risk 0.64cvss 9.8epss 0.02
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 40A774.
- risk 0.64cvss 9.8epss 0.02
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
- risk 0.64cvss 9.8epss 0.02
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.