VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 48 of 192
  • CVE-2023-0315HigJan 16, 2023
    risk 0.61cvss 8.8epss 0.98

    Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.

  • CVE-2020-28453CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.

  • CVE-2020-28437CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.

  • CVE-2020-28434CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.

  • CVE-2020-28435CriJul 25, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

  • CVE-2021-43339HigNov 3, 2021
    risk 0.61cvss 8.8epss 0.10

    In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.

  • CVE-2020-35798CriDec 30, 2020
    risk 0.61cvss 9.3epss 0.01

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900…

  • CVE-2019-6275HigMar 21, 2019
    risk 0.61cvss 8.8epss 0.13

    Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

  • CVE-2019-6272HigMar 21, 2019
    risk 0.61cvss 8.8epss 0.13

    Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

  • CVE-2017-6048HigMay 19, 2017
    risk 0.61cvss 8.8epss 0.16

    A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this…

  • CVE-2016-0861HigFeb 5, 2016
    risk 0.61cvss 8.8epss 0.14

    General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.

  • CVE-2026-52806CriJun 24, 2026
    risk 0.60cvss 9.9epss 0.01

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during…

  • CVE-2026-41090CriMay 22, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-44257CriMay 12, 2026
    risk 0.60cvss epss 0.00

    efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and…

  • CVE-2026-3854HigMar 10, 2026
    risk 0.60cvss 8.8epss 0.34

    An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were…

  • CVE-2025-59286CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59272CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

  • CVE-2025-59252CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-61584CriSep 30, 2025
    risk 0.60cvss epss 0.00

    serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the…

  • CVE-2025-50989CriAug 27, 2025
    risk 0.60cvss 9.1epss 0.08

    OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowing an…