VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 67 of 199
  • CVE-2023-45208HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.01

    A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers (within range of the repeater) to run shell commands as root during the setup process of the repeater, via a crafted SSID.…

  • CVE-2023-44827HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.

  • CVE-2023-45356HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform…

  • CVE-2023-45355HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This…

  • CVE-2023-45351HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039.

  • CVE-2023-42810CriSep 21, 2023
    risk 0.57cvss 9.8epss 0.02

    systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to…

  • CVE-2023-43138HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.

  • CVE-2023-43137HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.

  • CVE-2023-33136HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Azure DevOps Server Remote Code Execution Vulnerability

  • CVE-2023-38829HigSep 11, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.

  • CVE-2023-23564HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to execute commands.

  • CVE-2023-38902HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.03

    A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and…

  • CVE-2023-2910HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.02

    Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Affected products and versions…

  • CVE-2023-34213HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.01

    TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentially allow malicious users to execute…

  • CVE-2023-33239HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.01

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow…

  • CVE-2023-38921HigAug 7, 2023
    risk 0.57cvss 8.8epss 0.02

    Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via the firmwareRestore and firmwareServerip parameters.

  • CVE-2023-3718HigAug 1, 2023
    risk 0.57cvss 8.8epss 0.02

    An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This…

  • CVE-2023-24583HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.03

    Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these…

  • CVE-2023-24582HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.03

    Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these…

  • CVE-2023-24520HigJul 6, 2023
    risk 0.57cvss 8.8epss 0.04

    Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This…