VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 49 of 199
  • CVE-2023-5878CriFeb 6, 2025
    risk 0.61cvss —epss 0.01

    Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the…

  • CVE-2024-37186CriJan 14, 2025
    risk 0.61cvss 9.1epss 0.23

    An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2024-7397CriAug 5, 2024
    risk 0.61cvss —epss 0.01

    Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2.

  • CVE-2024-38492CriJul 15, 2024
    risk 0.61cvss —epss 0.01

    This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.

  • CVE-2023-1097CriMar 1, 2023
    risk 0.61cvss 9.3epss 0.01

    Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated…

  • CVE-2023-0315HigJan 16, 2023
    risk 0.61cvss 8.8epss 0.98

    Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.

  • CVE-2020-28453CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.

  • CVE-2020-28437CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.

  • CVE-2020-28434CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.

  • CVE-2020-28435CriJul 25, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

  • CVE-2021-43339HigNov 3, 2021
    risk 0.61cvss 8.8epss 0.10

    In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.

  • CVE-2020-35798CriDec 30, 2020
    risk 0.61cvss 9.3epss 0.01

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900…

  • CVE-2019-6275HigMar 21, 2019
    risk 0.61cvss 8.8epss 0.13

    Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

  • CVE-2019-6272HigMar 21, 2019
    risk 0.61cvss 8.8epss 0.13

    Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

  • CVE-2017-6048HigMay 19, 2017
    risk 0.61cvss 8.8epss 0.16

    A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this…

  • CVE-2016-0861HigFeb 5, 2016
    risk 0.61cvss 8.8epss 0.14

    General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.

  • CVE-2026-41090CriMay 22, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-44257CriMay 12, 2026
    risk 0.60cvss —epss 0.00

    efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and…

  • CVE-2026-3854HigMar 10, 2026
    risk 0.60cvss 8.8epss 0.40

    An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were…

  • CVE-2025-59286CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.