VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 64 of 199
  • CVE-2024-51301HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.

  • CVE-2024-51300HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.

  • CVE-2024-51299HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.

  • CVE-2024-51296HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.

  • CVE-2024-51257HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.00

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.

  • CVE-2024-51304HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.

  • CVE-2024-48441HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.02

    Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

  • CVE-2024-48440HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.02

    Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.

  • CVE-2024-44413HigOct 11, 2024
    risk 0.57cvss 8.8epss 0.03

    A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.

  • CVE-2024-43591HigOct 8, 2024
    risk 0.57cvss 8.7epss 0.02

    Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability

  • CVE-2024-47562HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged local attacker to…

  • CVE-2024-45682HigSep 17, 2024
    risk 0.57cvss 8.8epss 0.02

    There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

  • CVE-2024-44577HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.

  • CVE-2024-44574HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

  • CVE-2024-44572HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

  • CVE-2024-44570HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.00

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.

  • CVE-2024-44845HigSep 6, 2024
    risk 0.57cvss 8.8epss 0.02

    DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.

  • CVE-2024-44844HigSep 6, 2024
    risk 0.57cvss 8.8epss 0.02

    DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.

  • CVE-2024-42360CriAug 14, 2024
    risk 0.57cvss 9.8epss 0.01

    SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This…

  • CVE-2024-21879HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and <…