VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 171 of 329
  • CVE-2019-5414HigMar 21, 2019
    risk 0.53cvss 8.1epss 0.02

    If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.

  • CVE-2019-7298HigFeb 1, 2019
    risk 0.53cvss 8.1epss 0.10

    An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 request. This occurs when any HNAP API function triggers a call to the system function with…

  • CVE-2018-18600HigDec 31, 2018
    risk 0.53cvss 8.1epss 0.02

    The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.

  • CVE-2018-15722HigDec 20, 2018
    risk 0.53cvss 8.1epss 0.02

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.

  • CVE-2018-4021HigDec 3, 2018
    risk 0.53cvss 7.2epss 0.72

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to…

  • CVE-2018-18638HigOct 24, 2018
    risk 0.53cvss 8.1epss 0.03

    A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initialize endpoint.

  • CVE-2018-0453HigOct 5, 2018
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with root privileges on the Cisco Firepower…

  • CVE-2018-9077HigSep 28, 2018
    risk 0.53cvss 8.1epss 0.02

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed…

  • CVE-2018-9076HigSep 28, 2018
    risk 0.53cvss 8.1epss 0.02

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the…

  • CVE-2018-9075HigSep 28, 2018
    risk 0.53cvss 8.1epss 0.04

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be…

  • CVE-2018-7448HigFeb 26, 2018
    risk 0.53cvss 7.5epss 0.13

    Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.

  • CVE-2017-14705HigSep 22, 2017
    risk 0.53cvss 8.1epss 0.07

    DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type parameter to the tailDateFile function in /webservices/stream/tail.php. An iToken authentication parameter is required but can be…

  • CVE-2017-6710HigAug 17, 2017
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the Cisco Virtual Network Function (VNF) Element Manager could allow an authenticated, remote attacker to elevate privileges and run commands in the context of the root user on the server. The vulnerability is due to command settings that allow Cisco VNF…

  • CVE-2017-11318HigJul 17, 2017
    risk 0.53cvss 8.1epss 0.01

    Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed. In addition, the attacker can execute system commands remotely by abusing pre-backup events.

  • CVE-2017-6707HigJul 6, 2017
    risk 0.53cvss 8.2epss 0.01

    A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Core (VPC) Software could allow an authenticated, local attacker to break from the…

  • CVE-2016-1482HigSep 17, 2016
    risk 0.53cvss 8.1epss 0.04

    Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug ID CSCuy83130.

  • CVE-2026-55158criAug 17, 2026
    risk 0.52cvss epss

    ### Impact Versions of conflibot before `1.2.1` build `git` commands by string interpolation and run them through a shell. Several of the interpolated values are pull request branch names (`head.ref`), which are attacker-controlled: anyone can open a pull request (including…

  • CVE-2026-9044HigJul 31, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises…

  • CVE-2026-48165HigJun 12, 2026
    risk 0.52cvss 8.0epss 0.02

    MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or…

  • CVE-2026-48163HigJun 12, 2026
    risk 0.52cvss 8.0epss 0.01

    MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into…