VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 136 of 329
  • CVE-2024-21773HigJan 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.

  • CVE-2023-29048HigJan 8, 2024
    risk 0.57cvss 8.8epss 0.01

    A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and…

  • CVE-2023-41288HigJan 5, 2024
    risk 0.57cvss 8.8epss 0.01

    An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later

  • CVE-2022-39818HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.02

    In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.

  • CVE-2023-50466HigDec 19, 2023
    risk 0.57cvss 8.8epss 0.02

    An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.

  • CVE-2023-48782HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.03

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

  • CVE-2023-46157HigDec 8, 2023
    risk 0.57cvss 8.8epss 0.02

    File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.

  • CVE-2023-6357HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.01

    A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

  • CVE-2023-44304HigDec 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges could potentially exploit this vulnerability to escape the restricted shell and gain root access to the appliance.

  • CVE-2023-37927HigNov 30, 2023
    risk 0.57cvss 8.8epss 0.02

    The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to…

  • CVE-2023-6201HigNov 28, 2023
    risk 0.57cvss 8.8epss 0.02

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Computer System Panorama allows Command Injection. This issue affects Panorama: before 8.0.

  • CVE-2023-39295HigNov 10, 2023
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.3 and later

  • CVE-2023-41348HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary…

  • CVE-2023-41347HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary…

  • CVE-2023-41346HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary…

  • CVE-2023-41345HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary…

  • CVE-2023-20175HigNov 1, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level…

  • CVE-2023-23373HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: QUSBCam2 2.0.3 ( 2023/06/15 ) and later

  • CVE-2023-40145HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.

  • CVE-2023-43959HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.