VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 63 of 199
  • CVE-2024-13871HigMar 12, 2025
    risk 0.57cvss 8.8epss 0.01

    A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to…

  • CVE-2025-1497CriMar 10, 2025
    risk 0.57cvss 9.8epss 0.01

    A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it…

  • CVE-2025-0593HigFeb 14, 2025
    risk 0.57cvss 8.8epss 0.01

    The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the device.

  • CVE-2025-23239HigFeb 5, 2025
    risk 0.57cvss 8.7epss 0.01

    When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software…

  • CVE-2024-23971HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The…

  • CVE-2025-24150HigJan 27, 2025
    risk 0.57cvss 8.8epss 0.03

    A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.

  • CVE-2024-48419HigJan 27, 2025
    risk 0.57cvss 8.8epss 0.05

    Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an…

  • CVE-2024-54660HigJan 16, 2025
    risk 0.57cvss 8.7epss 0.01

    A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to…

  • CVE-2024-51442HigJan 8, 2025
    risk 0.57cvss 8.8epss 0.02

    Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

  • CVE-2024-39703HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API endpoint.

  • CVE-2024-51114HigDec 3, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file

  • CVE-2024-11665HigNov 24, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.

  • CVE-2024-38644HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

  • CVE-2023-24467HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.

  • CVE-2021-38117HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

  • CVE-2021-38116HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

  • CVE-2024-50853HigNov 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.

  • CVE-2024-50852HigNov 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.

  • CVE-2024-51254HigOct 31, 2024
    risk 0.57cvss 8.8epss 0.00

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.

  • CVE-2024-51258HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.