VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 133 of 329
  • CVE-2023-37407HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    IBM Aspera Orchestrator 4.0.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 260116.

  • CVE-2023-51585HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Voltronic Power ViewPower USBCommEx shutdown Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. User interaction is required to exploit this…

  • CVE-2023-50217HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 awsfile rm Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-50216HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 awsfile tar File Handling Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this…

  • CVE-2023-50215HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 nodered gz File Handling Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this…

  • CVE-2023-50214HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 nodered tar File Handling Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this…

  • CVE-2023-50213HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 nodered File Handling Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability.…

  • CVE-2023-50207HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 flupl filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-50206HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 flupl query_type edit Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability.…

  • CVE-2023-50205HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 awsfile chmod Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-50204HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 flupl pythonapp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 wireless routers. Authentication is not required to exploit this…

  • CVE-2023-50203HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 nodered chmod Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-50202HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 flupl pythonmodules Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 wireless routers. Authentication is not required to exploit this…

  • CVE-2023-50201HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 cfgsave upusb Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-50200HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 cfgsave backusb Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-50198HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link G416 cfgsave Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 wireless routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-44403HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DAP-1325 HNAP SetWLanRadioSettings Channel Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit…

  • CVE-2023-42123HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is required to exploit this vulnerability. The specific…

  • CVE-2023-42120HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    Control Web Panel dns_zone_editor Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is required to exploit this vulnerability. The specific…

  • CVE-2023-41201HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DAP-1325 HNAP SetSetupWizardStatus Enabled Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit…