VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 62 of 192
  • CVE-2024-48440HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.02

    Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.

  • CVE-2024-44413HigOct 11, 2024
    risk 0.57cvss 8.8epss 0.03

    A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.

  • CVE-2024-43591HigOct 8, 2024
    risk 0.57cvss 8.7epss 0.02

    Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability

  • CVE-2024-47562HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged local attacker to…

  • CVE-2024-45682HigSep 17, 2024
    risk 0.57cvss 8.8epss 0.02

    There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

  • CVE-2024-44577HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.

  • CVE-2024-44574HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

  • CVE-2024-44572HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

  • CVE-2024-44570HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.00

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.

  • CVE-2024-44845HigSep 6, 2024
    risk 0.57cvss 8.8epss 0.02

    DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.

  • CVE-2024-44844HigSep 6, 2024
    risk 0.57cvss 8.8epss 0.02

    DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.

  • CVE-2024-42360CriAug 14, 2024
    risk 0.57cvss 9.8epss 0.01

    SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This…

  • CVE-2024-21879HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and <…

  • CVE-2024-7177HigJul 29, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. Affected is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument langType leads to buffer overflow. It is possible to launch the…

  • CVE-2024-7174HigJul 29, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This affects the function setdeviceName of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument deviceMac/deviceName leads to buffer overflow. It is possible to…

  • CVE-2024-41320HigJul 22, 2024
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the get_apcli_conn_info function.

  • CVE-2024-30213HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.

  • CVE-2024-39571HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading SNMP configurations. This could allow an attacker with the right to…

  • CVE-2024-39570HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading VxLAN configurations. This could allow an authenticated attacker to…

  • CVE-2024-24551HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.