VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 163 of 329
  • CVE-2025-30286HigApr 8, 2025
    risk 0.55cvss 8.4epss 0.02

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A high-privileged attacker could…

  • CVE-2025-22495HigFeb 24, 2025
    risk 0.55cvss 8.4epss 0.00

    An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authenticated high privileged user having the ability to execute arbitrary commands. The vulnerability has been resolved in the version…

  • CVE-2024-56132HigFeb 5, 2025
    risk 0.55cvss 8.4epss 0.06

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12…

  • CVE-2025-24971CriFeb 4, 2025
    risk 0.55cvss epss 0.03

    DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, `/upload/init` endpoint. This vulnerability could allow an attacker to execute…

  • CVE-2024-53375HigDec 2, 2024
    risk 0.55cvss 8.0epss 0.41

    An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the activation of the…

  • CVE-2024-35519HigOct 14, 2024
    risk 0.55cvss 8.4epss 0.01

    Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.

  • CVE-2024-8755HigOct 11, 2024
    risk 0.55cvss 8.4epss 0.01

    Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12…

  • CVE-2024-39402HigAug 14, 2024
    risk 0.55cvss 8.4epss 0.02

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation…

  • CVE-2024-39401HigAug 14, 2024
    risk 0.55cvss 8.4epss 0.02

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation…

  • CVE-2024-32937HigJul 3, 2024
    risk 0.55cvss 8.1epss 0.26

    An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets…

  • CVE-2024-1628HigMay 14, 2024
    risk 0.55cvss 8.4epss 0.01

    OS command injection vulnerabilities in GE HealthCare ultrasound devices

  • CVE-2022-48684HigApr 27, 2024
    risk 0.55cvss 8.4epss 0.01

    An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for generating dynamic data. This could be abused to achieve code execution. Any user with access to create a search template can…

  • CVE-2023-25925HigFeb 28, 2024
    risk 0.55cvss 8.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.

  • CVE-2023-6926HigJan 23, 2024
    risk 0.55cvss 8.4epss 0.01

    There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.

  • CVE-2024-0778HigJan 22, 2024
    risk 0.55cvss 8.0epss 0.32

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this issue is the function setNatConfig of the file /Interface/DevManage/VM.php. The manipulation of the argument…

  • CVE-2023-52314CriJan 3, 2024
    risk 0.55cvss 9.6epss 0.01

    PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.

  • CVE-2023-52311CriJan 3, 2024
    risk 0.55cvss 9.6epss 0.01

    PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.

  • CVE-2023-52310CriJan 3, 2024
    risk 0.55cvss 9.6epss 0.01

    PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.

  • CVE-2023-46306HigOct 22, 2023
    risk 0.55cvss 8.4epss 0.01

    The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: shell metacharacters in the /admin/gnssAutoAlign.php device_id parameter. This occurs because…

  • CVE-2023-25539HigMay 31, 2023
    risk 0.55cvss 8.4epss 0.01

    Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the…