CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,970)
page 34 of 199| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24138 | Cri | 0.64 | 9.8 | 0.02 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function. | ||
| CVE-2023-24612 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2023 | The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option. | ||
| CVE-2022-39073 | Cri | 0.64 | 9.8 | 0.03 | Jan 6, 2023 | There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands. | ||
| CVE-2022-32665 | Cri | 0.64 | 9.8 | 0.02 | Jan 3, 2023 | In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124. | ||
| CVE-2022-31702 | Cri | 0.64 | 9.8 | 0.02 | Dec 14, 2022 | vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication. | ||
| CVE-2022-44832 | Cri | 0.64 | 9.8 | 0.04 | Dec 14, 2022 | D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function. | ||
| CVE-2022-46404 | Cri | 0.64 | 9.8 | 0.02 | Dec 13, 2022 | A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve… | ||
| CVE-2020-23583 | Cri | 0.64 | 9.8 | 0.02 | Nov 23, 2022 | OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise… | ||
| CVE-2022-36786 | Cri | 0.64 | 9.9 | 0.01 | Nov 17, 2022 | DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router. | ||
| CVE-2022-40752 | Cri | 0.64 | 9.8 | 0.02 | Nov 16, 2022 | IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687. | ||
| CVE-2022-43109 | Cri | 0.64 | 9.8 | 0.04 | Nov 3, 2022 | D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet. | ||
| CVE-2022-37425 | Cri | 0.64 | 9.9 | 0.02 | Oct 28, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion. | ||
| CVE-2022-43367 | Cri | 0.64 | 9.8 | 0.05 | Oct 27, 2022 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function. | ||
| CVE-2022-32765 | Cri | 0.64 | 9.8 | 0.04 | Oct 25, 2022 | An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this… | ||
| CVE-2022-42897 | Cri | 0.64 | 9.8 | 0.02 | Oct 13, 2022 | Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected. | ||
| CVE-2022-40100 | Cri | 0.64 | 9.8 | 0.02 | Sep 23, 2022 | Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function. | ||
| CVE-2022-37125 | Cri | 0.64 | 9.8 | 0.03 | Aug 31, 2022 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost. | ||
| CVE-2022-36559 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2022 | Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi. | ||
| CVE-2022-36556 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01. | ||
| CVE-2022-36554 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2022 | A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges. |
- risk 0.64cvss 9.8epss 0.02
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.
- risk 0.64cvss 9.8epss 0.01
The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.
- risk 0.64cvss 9.8epss 0.03
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.02
In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124.
- risk 0.64cvss 9.8epss 0.02
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve…
- risk 0.64cvss 9.8epss 0.02
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise…
- risk 0.64cvss 9.9epss 0.01
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
- risk 0.64cvss 9.8epss 0.02
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.
- risk 0.64cvss 9.9epss 0.02
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.
- risk 0.64cvss 9.8epss 0.05
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.
- risk 0.64cvss 9.8epss 0.04
An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this…
- risk 0.64cvss 9.8epss 0.02
Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.
- risk 0.64cvss 9.8epss 0.02
Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.
- risk 0.64cvss 9.8epss 0.03
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
- risk 0.64cvss 9.8epss 0.02
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.
- risk 0.64cvss 9.8epss 0.02
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.