VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 37 of 192
  • CVE-2021-46231CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.

  • CVE-2021-46230CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.

  • CVE-2021-46229CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter.

  • CVE-2021-46228CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.

  • CVE-2021-46227CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerability allows attackers to execute arbitrary commands via the proxy_srv, proxy_srvport, proxy_lanip, proxy_lanport parameters.

  • CVE-2021-46226CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.

  • CVE-2021-45998CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-45990CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.

  • CVE-2021-45742CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2021-45738CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.

  • CVE-2021-45733CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.

  • CVE-2021-44882CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44881CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44880CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44247CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom…

  • CVE-2021-46560CriJan 26, 2022
    risk 0.64cvss 9.8epss 0.04

    The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.

  • CVE-2021-44735CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.07

    Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.

  • CVE-2021-33963CriJan 15, 2022
    risk 0.64cvss 9.8epss 0.03

    China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

  • CVE-2021-45456CriJan 6, 2022
    risk 0.64cvss 9.8epss 0.89

    Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may cause an illegal…

  • CVE-2021-45617CriDec 26, 2021
    risk 0.64cvss 9.8epss 0.02

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX7500 before 1.0.0.72, R6400 before 1.0.1.68, R6900P before 1.3.2.132, R7000 before 1.0.11.116, R7000P…