VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 66 of 199
  • CVE-2024-30891HigApr 5, 2024
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.

  • CVE-2024-30637HigMar 29, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.

  • CVE-2024-28041HigMar 25, 2024
    risk 0.57cvss 8.8epss 0.01

    HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.

  • CVE-2024-29366HigMar 22, 2024
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.

  • CVE-2024-28353HigMar 15, 2024
    risk 0.57cvss 8.8epss 0.02

    There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.

  • CVE-2023-24330HigFeb 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.

  • CVE-2024-23346CriFeb 21, 2024
    risk 0.57cvss 9.3epss 0.04

    Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method…

  • CVE-2024-24301HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.02

    Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.

  • CVE-2024-22093HigFeb 14, 2024
    risk 0.57cvss 8.7epss 0.01

    When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached…

  • CVE-2023-40263HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.

  • CVE-2024-22903HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.02

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

  • CVE-2024-22900HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.02

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

  • CVE-2023-48791HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via…

  • CVE-2023-47576HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.

  • CVE-2023-49213HigNov 23, 2023
    risk 0.57cvss 8.8epss 0.02

    The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.

  • CVE-2023-43322HigOct 28, 2023
    risk 0.57cvss 8.8epss 0.01

    ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.

  • CVE-2023-38193HigOct 21, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.

  • CVE-2023-32632HigOct 11, 2023
    risk 0.57cvss 8.8epss 0.01

    A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-36415HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.02

    Azure Identity SDK Remote Code Execution Vulnerability

  • CVE-2023-36414HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.02

    Azure Identity SDK Remote Code Execution Vulnerability