VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 103 of 327
  • CVE-2021-33514HigMay 21, 2021
    risk 0.58cvss 8.8epss 0.08

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a CGI application, as demonstrated by setup.cgi?token=';$HTTP_USER_AGENT;' with an OS command in the User-Agent field. This affects…

  • CVE-2020-21999HigMay 4, 2021
    risk 0.58cvss 8.8epss 0.05

    iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' POST parameter in pingTest PHP…

  • CVE-2020-21992HigApr 29, 2021
    risk 0.58cvss 8.8epss 0.05

    Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called with the 'testemail' module through web.cgi binary. The vulnerable CGI binary…

  • CVE-2021-27249HigApr 14, 2021
    risk 0.58cvss 8.8epss 0.05

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of CGI…

  • CVE-2020-21883HigApr 9, 2021
    risk 0.58cvss 8.8epss 0.04

    Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.

  • CVE-2021-25162HigMar 30, 2021
    risk 0.58cvss 8.1epss 0.26

    A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant…

  • CVE-2021-28144HigMar 11, 2021
    risk 0.58cvss 8.8epss 0.06

    prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.

  • CVE-2020-27575HigMar 8, 2021
    risk 0.58cvss 8.8epss 0.03

    Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form contains a parameter vulnerable to command injection due to insufficient…

  • CVE-2021-21315HigKEVFeb 16, 2021
    risk 0.58cvss 7.1epss 0.91

    The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was…

  • CVE-2020-24899HigFeb 15, 2021
    risk 0.58cvss 8.8epss 0.17

    Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp query.

  • CVE-2021-25310HigFeb 2, 2021
    risk 0.58cvss 8.8epss 0.05

    The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint. This occurs…

  • CVE-2020-23826HigJan 26, 2021
    risk 0.58cvss 8.8epss 0.13

    The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176

  • CVE-2020-19664HigDec 31, 2020
    risk 0.58cvss 8.8epss 0.05

    DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.

  • CVE-2019-14479HigDec 16, 2020
    risk 0.58cvss 8.8epss 0.04

    AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.

  • CVE-2020-25499HigDec 9, 2020
    risk 0.58cvss 8.8epss 0.04

    TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.

  • CVE-2020-26878HigOct 26, 2020
    risk 0.58cvss 8.8epss 0.12

    Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.

  • CVE-2020-13778HigOct 19, 2020
    risk 0.58cvss 8.8epss 0.04

    rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplate.php or lib/ajaxHandlers/ajaxEditTemplate.php.

  • CVE-2020-17406HigOct 13, 2020
    risk 0.58cvss 8.8epss 0.05

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of the ping parameter provided to…

  • CVE-2020-26582HigOct 6, 2020
    risk 0.58cvss 8.8epss 0.05

    D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value for ping (aka res_config_action=3&res_config_id=18).

  • CVE-2020-3430HigSep 4, 2020
    risk 0.58cvss 8.8epss 0.04

    A vulnerability in the application protocol handling features of Cisco Jabber for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper handling of input to the application protocol handlers. An attacker could…