VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,834)

page 30 of 192
  • CVE-2023-28489CriApr 11, 2023
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled.…

  • CVE-2023-26978CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.

  • CVE-2023-26848CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.

  • CVE-2023-29475CriApr 6, 2023
    risk 0.64cvss 9.8epss 0.01

    inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543.

  • CVE-2023-29474CriApr 6, 2023
    risk 0.64cvss 9.8epss 0.01

    inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23552.

  • CVE-2023-29473CriApr 6, 2023
    risk 0.64cvss 9.8epss 0.01

    webservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23710.

  • CVE-2023-26866CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.02

    GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands are executed using pre-login execution and executed with root privileges allowing complete…

  • CVE-2023-28677CriApr 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able to configure Freestyle projects to…

  • CVE-2023-26822CriApr 1, 2023
    risk 0.64cvss 9.8epss 0.03

    D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.

  • CVE-2023-27232CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg.

  • CVE-2023-27231CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.

  • CVE-2023-27229CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.

  • CVE-2023-26800CriMar 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function.

  • CVE-2023-23149CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    DEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability.

  • CVE-2022-28496CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-28497CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2023-27135CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.

  • CVE-2023-27078CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to the tftp endpoint.

  • CVE-2023-27224CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.

  • CVE-2023-27240CriMar 15, 2023
    risk 0.64cvss 9.8epss 0.03

    Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.