VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 65 of 192
  • CVE-2023-43137HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.

  • CVE-2023-33136HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Azure DevOps Server Remote Code Execution Vulnerability

  • CVE-2023-38829HigSep 11, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.

  • CVE-2023-23564HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to execute commands.

  • CVE-2023-38902HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.03

    A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and…

  • CVE-2023-2910HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.02

    Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Affected products and versions…

  • CVE-2023-34213HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.01

    TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentially allow malicious users to execute…

  • CVE-2023-33239HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.01

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow…

  • CVE-2023-38921HigAug 7, 2023
    risk 0.57cvss 8.8epss 0.02

    Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via the firmwareRestore and firmwareServerip parameters.

  • CVE-2023-3718HigAug 1, 2023
    risk 0.57cvss 8.8epss 0.02

    An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This…

  • CVE-2023-24583HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.03

    Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these…

  • CVE-2023-24582HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.03

    Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these…

  • CVE-2023-24520HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.04

    Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This…

  • CVE-2023-24519HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.04

    Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This…

  • CVE-2023-26134CriJun 28, 2023
    risk 0.57cvss 9.8epss 0.04

    Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject…

  • CVE-2023-26298HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2023-26297HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2023-26296HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2023-35035HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23557.

  • CVE-2023-35033HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23556.