VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 14 of 324
  • CVE-2019-12986CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.40

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

  • CVE-2019-12985CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.40

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

  • CVE-2018-19986CriMay 13, 2019
    risk 0.67cvss 9.8epss 0.42

    In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the…

  • CVE-2019-9194CriFeb 26, 2019
    risk 0.67cvss 9.8epss 0.97

    elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

  • CVE-2018-11143CriJun 2, 2018
    risk 0.67cvss 9.8epss 0.37

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).

  • CVE-2018-1000006HigJan 24, 2018
    risk 0.67cvss 8.8epss 0.84

    GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution…

  • CVE-2017-16666HigJan 5, 2018
    risk 0.67cvss 8.8epss 0.80

    Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NOTE: this issue can be exploited without authentication by leveraging the user registration feature.

  • CVE-2017-8220CriApr 25, 2017
    risk 0.67cvss 9.9epss 0.37

    TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data.

  • CVE-1999-0043CriDec 4, 1996
    risk 0.67cvss 9.8epss 0.45

    Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

  • CVE-2025-58034HigKEVNov 18, 2025
    risk 0.66cvss 7.2epss 0.56

    An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0…

  • CVE-2024-13985CriAug 27, 2025
    risk 0.66cvss epss 0.13

    A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is…

  • CVE-2025-34043CriJun 26, 2025
    risk 0.66cvss epss 0.08

    A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability allows unauthenticated attackers to pass arbitrary commands to the underlying operating system via…

  • CVE-2025-34041CriJun 24, 2025
    risk 0.66cvss epss 0.07

    An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the…

  • CVE-2025-34036CriJun 24, 2025
    risk 0.66cvss 9.8epss 0.26

    An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. The web interface fails to sanitize input in the URI path passed to the language extraction…

  • CVE-2024-51151CriNov 21, 2024
    risk 0.66cvss 9.8epss 0.30

    D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.

  • CVE-2024-10443CriNov 15, 2024
    risk 0.66cvss 9.8epss 0.28

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute…

  • CVE-2024-8190HigKEVSep 10, 2024
    risk 0.66cvss 7.2epss 0.89

    An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

  • CVE-2024-8504HigSep 10, 2024
    risk 0.66cvss 8.8epss 0.76

    An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

  • CVE-2024-4884CriJun 25, 2024
    risk 0.66cvss 9.8epss 0.24

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

  • CVE-2024-27172CriJun 14, 2024
    risk 0.66cvss 9.8epss 0.27

    Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.