CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,970)
page 66 of 199| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30891 | Hig | 0.57 | 8.8 | 0.02 | Apr 5, 2024 | A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution. | ||
| CVE-2024-30637 | Hig | 0.57 | 8.8 | 0.02 | Mar 29, 2024 | Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter. | ||
| CVE-2024-28041 | Hig | 0.57 | 8.8 | 0.01 | Mar 25, 2024 | HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command. | ||
| CVE-2024-29366 | Hig | 0.57 | 8.8 | 0.02 | Mar 22, 2024 | A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03. | ||
| CVE-2024-28353 | Hig | 0.57 | 8.8 | 0.02 | Mar 15, 2024 | There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges. | ||
| CVE-2023-24330 | Hig | 0.57 | 8.8 | 0.01 | Feb 21, 2024 | Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/. | ||
| CVE-2024-23346 | Cri | 0.57 | 9.3 | 0.04 | Feb 21, 2024 | Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method… | ||
| CVE-2024-24301 | Hig | 0.57 | 8.8 | 0.02 | Feb 14, 2024 | Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges. | ||
| CVE-2024-22093 | Hig | 0.57 | 8.7 | 0.01 | Feb 14, 2024 | When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached… | ||
| CVE-2023-40263 | Hig | 0.57 | 8.8 | 0.01 | Feb 8, 2024 | An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp. | ||
| CVE-2024-22903 | Hig | 0.57 | 8.8 | 0.02 | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function. | ||
| CVE-2024-22900 | Hig | 0.57 | 8.8 | 0.02 | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function. | ||
| CVE-2023-48791 | Hig | 0.57 | 8.8 | 0.01 | Dec 13, 2023 | An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via… | ||
| CVE-2023-47576 | Hig | 0.57 | 8.8 | 0.02 | Dec 13, 2023 | An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface. | ||
| CVE-2023-49213 | Hig | 0.57 | 8.8 | 0.02 | Nov 23, 2023 | The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1. | ||
| CVE-2023-43322 | Hig | 0.57 | 8.8 | 0.01 | Oct 28, 2023 | ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/. | ||
| CVE-2023-38193 | Hig | 0.57 | 8.8 | 0.01 | Oct 21, 2023 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line. | ||
| CVE-2023-32632 | Hig | 0.57 | 8.8 | 0.01 | Oct 11, 2023 | A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability. | ||
| CVE-2023-36415 | Hig | 0.57 | 8.8 | 0.02 | Oct 10, 2023 | Azure Identity SDK Remote Code Execution Vulnerability | ||
| CVE-2023-36414 | Hig | 0.57 | 8.8 | 0.02 | Oct 10, 2023 | Azure Identity SDK Remote Code Execution Vulnerability |
- risk 0.57cvss 8.8epss 0.02
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.
- risk 0.57cvss 8.8epss 0.02
Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.
- risk 0.57cvss 8.8epss 0.01
HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.
- risk 0.57cvss 8.8epss 0.02
A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.
- risk 0.57cvss 8.8epss 0.02
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.
- risk 0.57cvss 8.8epss 0.01
Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.
- risk 0.57cvss 9.3epss 0.04
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method…
- risk 0.57cvss 8.8epss 0.02
Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.
- risk 0.57cvss 8.7epss 0.01
When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.
- risk 0.57cvss 8.8epss 0.02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
- risk 0.57cvss 8.8epss 0.02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
- risk 0.57cvss 8.8epss 0.01
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via…
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.
- risk 0.57cvss 8.8epss 0.02
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
- risk 0.57cvss 8.8epss 0.01
ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
- risk 0.57cvss 8.8epss 0.01
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.
- risk 0.57cvss 8.8epss 0.02
Azure Identity SDK Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Azure Identity SDK Remote Code Execution Vulnerability