VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 7 of 191
  • CVE-2025-45988CriJun 13, 2025
    risk 0.65cvss 9.8epss 0.11

    Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the cmd parameter in the…

  • CVE-2025-44084CriMay 20, 2025
    risk 0.65cvss 9.8epss 0.18

    D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.

  • CVE-2024-12971HigMar 17, 2025
    risk 0.65cvss 8.8epss 0.58

    Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

  • CVE-2025-0868CriFeb 20, 2025
    risk 0.65cvss epss 0.17

    A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from…

  • CVE-2024-55547CriDec 10, 2024
    risk 0.65cvss 9.8epss 0.17

    SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.

  • CVE-2024-20418CriNov 6, 2024
    risk 0.65cvss 10.0epss 0.03

    A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the…

  • CVE-2024-9264CriOct 18, 2024
    risk 0.65cvss 9.9epss 0.95

    The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user…

  • CVE-2024-45066CriSep 25, 2024
    risk 0.65cvss 10.0epss 0.01

    A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.

  • CVE-2024-43693CriSep 25, 2024
    risk 0.65cvss 10.0epss 0.01

    A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.

  • CVE-2024-46048CriSep 13, 2024
    risk 0.65cvss 9.8epss 0.11

    Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

  • CVE-2024-44466CriSep 11, 2024
    risk 0.65cvss 9.8epss 0.11

    COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.

  • CVE-2024-44400CriSep 4, 2024
    risk 0.65cvss 9.8epss 0.14

    A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.

  • CVE-2024-42905CriAug 28, 2024
    risk 0.65cvss 9.8epss 0.15

    Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file.

  • CVE-2024-39226CriAug 6, 2024
    risk 0.65cvss 9.8epss 0.21

    GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerability can be exploited to…

  • CVE-2024-33344CriApr 26, 2024
    risk 0.65cvss 9.8epss 0.20

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

  • CVE-2024-32766CriApr 26, 2024
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build…

  • CVE-2024-28354CriMar 15, 2024
    risk 0.65cvss 10.0epss 0.02

    There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.

  • CVE-2024-25850CriFeb 22, 2024
    risk 0.65cvss 9.8epss 0.19

    Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter

  • CVE-2024-22651CriJan 24, 2024
    risk 0.65cvss 9.8epss 0.20

    There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.

  • CVE-2023-49237CriJan 9, 2024
    risk 0.65cvss 9.8epss 0.19

    An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.