VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 7 of 199
  • CVE-2025-15471CriJan 7, 2026
    risk 0.65cvss 9.8epss 0.14

    A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public…

  • CVE-2025-14707CriDec 15, 2025
    risk 0.65cvss 9.8epss 0.19

    A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. Performing manipulation of the argument params results in command injection. The attack may be initiated…

  • CVE-2025-14706CriDec 15, 2025
    risk 0.65cvss 9.8epss 0.19

    A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the component NETREBOOT Interface. Such manipulation leads to command injection. The attack can be launched remotely. The exploit is…

  • CVE-2025-14705CriDec 15, 2025
    risk 0.65cvss 9.8epss 0.17

    A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulation of the argument params causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed…

  • CVE-2025-45988CriJun 13, 2025
    risk 0.65cvss 9.8epss 0.11

    Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the cmd parameter in the…

  • CVE-2025-44084CriMay 20, 2025
    risk 0.65cvss 9.8epss 0.20

    D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.

  • CVE-2024-12971HigMar 17, 2025
    risk 0.65cvss 8.8epss 0.61

    Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

  • CVE-2025-0868CriFeb 20, 2025
    risk 0.65cvss —epss 0.17

    A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from…

  • CVE-2024-55547CriDec 10, 2024
    risk 0.65cvss 9.8epss 0.17

    SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.

  • CVE-2024-20418CriNov 6, 2024
    risk 0.65cvss 10.0epss 0.03

    A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the…

  • CVE-2024-9264CriOct 18, 2024
    risk 0.65cvss 9.9epss 0.95

    The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user…

  • CVE-2024-45066CriSep 25, 2024
    risk 0.65cvss 10.0epss 0.01

    A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.

  • CVE-2024-43693CriSep 25, 2024
    risk 0.65cvss 10.0epss 0.01

    A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.

  • CVE-2024-46048CriSep 13, 2024
    risk 0.65cvss 9.8epss 0.11

    Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

  • CVE-2024-44466CriSep 11, 2024
    risk 0.65cvss 9.8epss 0.11

    COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.

  • CVE-2024-44400CriSep 4, 2024
    risk 0.65cvss 9.8epss 0.14

    A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.

  • CVE-2024-42905CriAug 28, 2024
    risk 0.65cvss 9.8epss 0.15

    Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file.

  • CVE-2024-39226CriAug 6, 2024
    risk 0.65cvss 9.8epss 0.20

    GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerability can be exploited to…

  • CVE-2024-33344CriApr 26, 2024
    risk 0.65cvss 9.8epss 0.20

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

  • CVE-2024-32766CriApr 26, 2024
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build…