VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 69 of 192
  • CVE-2021-43161HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

  • CVE-2021-43160HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.

  • CVE-2021-43159HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..

  • CVE-2022-24437CriMay 1, 2022
    risk 0.57cvss 9.8epss 0.04

    The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to…

  • CVE-2021-34592HigApr 27, 2022
    risk 0.57cvss 8.8epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.

  • CVE-2022-0999HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.

  • CVE-2022-22688HigMar 25, 2022
    risk 0.57cvss 8.8epss 0.02

    Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

  • CVE-2021-41001HigMar 2, 2022
    risk 0.57cvss 8.8epss 0.03

    An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series,…

  • CVE-2021-41000HigMar 2, 2022
    risk 0.57cvss 8.8epss 0.03

    Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series,…

  • CVE-2021-41599HigFeb 18, 2022
    risk 0.57cvss 8.8epss 0.02

    A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server…

  • CVE-2021-41552HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.

  • CVE-2021-33965HigJan 18, 2022
    risk 0.57cvss 8.8epss 0.03

    China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote…

  • CVE-2021-33964HigJan 18, 2022
    risk 0.57cvss 8.8epss 0.03

    China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerability to execute remote…

  • CVE-2021-42559HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is…

  • CVE-2021-45553HigDec 26, 2021
    risk 0.57cvss 8.7epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126, R6900P before 1.3.2.126, and R7000P before 1.3.2.126.

  • CVE-2021-3621HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.03

    A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root…

  • CVE-2021-45459CriDec 22, 2021
    risk 0.57cvss 9.8epss 0.04

    lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.

  • CVE-2021-43469HigDec 6, 2021
    risk 0.57cvss 8.8epss 0.02

    VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.

  • CVE-2021-37102HigNov 23, 2021
    risk 0.57cvss 8.8epss 0.01

    There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user…

  • CVE-2021-34362HigOct 22, 2021
    risk 0.57cvss 8.7epss 0.01

    A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of Media Streaming…