VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,834)

page 33 of 192
  • CVE-2022-31702CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.02

    vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.

  • CVE-2022-44832CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

  • CVE-2022-46404CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve…

  • CVE-2020-23583CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise…

  • CVE-2022-36786CriNov 17, 2022
    risk 0.64cvss 9.9epss 0.01

    DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

  • CVE-2022-40752CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.02

    IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.

  • CVE-2022-43109CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.

  • CVE-2022-37425CriOct 28, 2022
    risk 0.64cvss 9.9epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.

  • CVE-2022-43367CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.05

    IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.

  • CVE-2022-32765CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this…

  • CVE-2022-42897CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.02

    Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.

  • CVE-2022-40100CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.

  • CVE-2022-37125CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.03

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

  • CVE-2022-36559CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.

  • CVE-2022-36556CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

  • CVE-2022-36554CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.

  • CVE-2022-21165CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.03

    All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.

  • CVE-2022-36523CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

  • CVE-2022-35518CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nas_disk.shtml.

  • CVE-2022-34660CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter…