CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,573)
page 130 of 329| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-50853 | Hig | 0.57 | 8.8 | 0.02 | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function. | ||
| CVE-2024-50852 | Hig | 0.57 | 8.8 | 0.02 | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function. | ||
| CVE-2024-41992 | Hig | 0.57 | 8.8 | 0.03 | Nov 11, 2024 | Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP… | ||
| CVE-2024-50809 | Hig | 0.57 | 8.8 | 0.01 | Nov 8, 2024 | The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands | ||
| CVE-2024-51735 | — | Hig | 0.57 | — | 0.00 | Nov 5, 2024 | Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when viewing results from the workflow, allowing commands to be executed on the server. When using a workflow that contains the summary module, it generates reports… | |
| CVE-2024-51023 | Hig | 0.57 | 8.8 | 0.01 | Nov 5, 2024 | D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | ||
| CVE-2024-51248 | Hig | 0.57 | 8.8 | 0.01 | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function. | ||
| CVE-2024-51247 | Hig | 0.57 | 8.8 | 0.01 | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function. | ||
| CVE-2024-51245 | Hig | 0.57 | 8.8 | 0.01 | Nov 1, 2024 | In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function. | ||
| CVE-2024-51244 | Hig | 0.57 | 8.8 | 0.01 | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function. | ||
| CVE-2024-36060 | Hig | 0.57 | 8.8 | 0.01 | Oct 30, 2024 | EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters. | ||
| CVE-2024-48826 | Hig | 0.57 | 8.8 | 0.02 | Oct 28, 2024 | Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code. | ||
| CVE-2024-48825 | Hig | 0.57 | 8.8 | 0.02 | Oct 28, 2024 | Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code. | ||
| CVE-2024-10202 | Hig | 0.57 | 8.8 | 0.01 | Oct 21, 2024 | Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands. | ||
| CVE-2024-33368 | Hig | 0.57 | 8.8 | 0.01 | Sep 27, 2024 | An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen | ||
| CVE-2024-43778 | Hig | 0.57 | 8.8 | 0.01 | Sep 18, 2024 | OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | ||
| CVE-2024-45682 | Hig | 0.57 | 8.8 | 0.02 | Sep 17, 2024 | There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system. | ||
| CVE-2024-20398 | Hig | 0.57 | 8.8 | 0.00 | Sep 11, 2024 | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are… | ||
| CVE-2024-6091 | Cri | 0.57 | 9.8 | 0.01 | Sep 11, 2024 | A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as 'whoami' and '/bin/whoami'. An attacker can circumvent this… | ||
| CVE-2024-7699 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2024 | An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data. |
- risk 0.57cvss 8.8epss 0.02
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
- risk 0.57cvss 8.8epss 0.02
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.
- risk 0.57cvss 8.8epss 0.03
Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP…
- risk 0.57cvss 8.8epss 0.01
The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands
- risk 0.57cvss —epss 0.00
Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when viewing results from the workflow, allowing commands to be executed on the server. When using a workflow that contains the summary module, it generates reports…
- risk 0.57cvss 8.8epss 0.01
D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
- risk 0.57cvss 8.8epss 0.01
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
- risk 0.57cvss 8.8epss 0.01
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
- risk 0.57cvss 8.8epss 0.01
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
- risk 0.57cvss 8.8epss 0.01
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
- risk 0.57cvss 8.8epss 0.01
EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.
- risk 0.57cvss 8.8epss 0.02
Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
- risk 0.57cvss 8.8epss 0.02
Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
- risk 0.57cvss 8.8epss 0.01
Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
- risk 0.57cvss 8.8epss 0.01
An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen
- risk 0.57cvss 8.8epss 0.01
OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- risk 0.57cvss 8.8epss 0.02
There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.
- risk 0.57cvss 8.8epss 0.00
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are…
- risk 0.57cvss 9.8epss 0.01
A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as 'whoami' and '/bin/whoami'. An attacker can circumvent this…
- risk 0.57cvss 8.8epss 0.01
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.