VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,834)

page 31 of 192
  • CVE-2021-33360CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).

  • CVE-2023-22750CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22749CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22748CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22747CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2022-48259CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges.

  • CVE-2022-48255CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution.

  • CVE-2023-23080CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS…

  • CVE-2023-24184CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.

  • CVE-2022-40021CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.

  • CVE-2022-45701HigFeb 17, 2023
    risk 0.64cvss 8.8epss 0.42

    Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

  • CVE-2023-24238CriFeb 16, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.

  • CVE-2023-24236CriFeb 16, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.

  • CVE-2023-24161CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

  • CVE-2023-24160CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.

  • CVE-2023-24159CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.

  • CVE-2021-31575CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2021-31574CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2021-31573CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2023-24276CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.