VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 34 of 199
  • CVE-2023-24138CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.

  • CVE-2023-24612CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.

  • CVE-2022-39073CriJan 6, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

  • CVE-2022-32665CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.02

    In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124.

  • CVE-2022-31702CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.02

    vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.

  • CVE-2022-44832CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

  • CVE-2022-46404CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve…

  • CVE-2020-23583CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise…

  • CVE-2022-36786CriNov 17, 2022
    risk 0.64cvss 9.9epss 0.01

    DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

  • CVE-2022-40752CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.02

    IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.

  • CVE-2022-43109CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.

  • CVE-2022-37425CriOct 28, 2022
    risk 0.64cvss 9.9epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.

  • CVE-2022-43367CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.05

    IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.

  • CVE-2022-32765CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this…

  • CVE-2022-42897CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.02

    Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.

  • CVE-2022-40100CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.

  • CVE-2022-37125CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.03

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

  • CVE-2022-36559CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.

  • CVE-2022-36556CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

  • CVE-2022-36554CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.