VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,529)

page 111 of 327
  • CVE-2017-2841HigJun 27, 2017
    risk 0.58cvss 8.8epss 0.06

    An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file…

  • CVE-2017-2828HigJun 21, 2017
    risk 0.58cvss 8.8epss 0.08

    An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation…

  • CVE-2017-2827HigJun 21, 2017
    risk 0.58cvss 8.8epss 0.08

    An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation…

  • CVE-2017-6683HigJun 13, 2017
    risk 0.58cvss 8.8epss 0.06

    A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Command Execution…

  • CVE-2016-5313HigApr 12, 2017
    risk 0.58cvss 8.8epss 0.05

    Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.

  • CVE-2017-6970HigMar 22, 2017
    risk 0.58cvss 8.4epss 0.02

    AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-104863.

  • CVE-2016-1000216HigOct 10, 2016
    risk 0.58cvss 8.8epss 0.07

    Ruckus Wireless H500 web management interface authenticated command injection

  • CVE-2016-4965HigSep 21, 2016
    risk 0.58cvss 8.8epss 0.04

    Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosis_control.php.

  • CVE-2026-45018CriAug 25, 2026
    risk 0.57cvss 9.8epss

    Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio…

  • CVE-2026-50112HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.00

    SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be…

  • CVE-2026-18264HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.01

    NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2026-16932HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable.

  • CVE-2026-77080HigAug 20, 2026
    risk 0.57cvss epss 0.00

    n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's…

  • CVE-2026-53545CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend/ssh/tunnel.ts interpolates endpointPort, sourcePort, endpointUsername, and…

  • CVE-2026-16865HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection.

  • CVE-2026-16848HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options.

  • CVE-2026-16844HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16842HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-71961HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.03

    Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary…

  • CVE-2026-54795HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.02

    Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…