VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 49 of 192
  • CVE-2024-54794CriJan 21, 2025
    risk 0.60cvss 9.1epss 0.13

    The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

  • CVE-2024-39783CriJan 14, 2025
    risk 0.60cvss 9.1epss 0.04

    Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these…

  • CVE-2024-39781CriJan 14, 2025
    risk 0.60cvss 9.1epss 0.04

    Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these…

  • CVE-2024-39765CriJan 14, 2025
    risk 0.60cvss 9.1epss 0.05

    Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2024-39763CriJan 14, 2025
    risk 0.60cvss 9.1epss 0.05

    Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2024-39762CriJan 14, 2025
    risk 0.60cvss 9.1epss 0.06

    Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2024-39367CriJan 14, 2025
    risk 0.60cvss 9.1epss 0.08

    An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2024-39360CriJan 14, 2025
    risk 0.60cvss 9.1epss 0.12

    An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2024-11772CriDec 10, 2024
    risk 0.60cvss 9.1epss 0.08

    Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-44334HigSep 9, 2024
    risk 0.60cvss 8.8epss 0.32

    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of…

  • CVE-2024-42348CriAug 2, 2024
    risk 0.60cvss 9.3epss 0.01

    FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.

  • CVE-2024-7029HigAug 2, 2024
    risk 0.60cvss 8.8epss 0.39

    Commands can be injected over the network and executed without authentication.

  • CVE-2024-37642CriJun 14, 2024
    risk 0.60cvss 9.1epss 0.11

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .

  • CVE-2023-23369CriNov 3, 2023
    risk 0.60cvss 9.0epss 0.15

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console…

  • CVE-2023-33782HigJun 7, 2023
    risk 0.60cvss 8.8epss 0.37

    D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

  • CVE-2020-24561CriSep 15, 2020
    risk 0.60cvss 9.1epss 0.05

    A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX console to exploit this vulnerability.

  • CVE-2019-12650HigSep 25, 2019
    risk 0.60cvss 8.8epss 0.29

    Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section…

  • CVE-2026-75094CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.02

    A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the…

  • CVE-2026-5433CriMay 21, 2026
    risk 0.59cvss 9.1epss 0.01

    Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).  Honeywell recommends updating to the most recent…

  • CVE-2025-60021CriJan 16, 2026
    risk 0.59cvss 9.8epss 0.25

    Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate the user-provided…