VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 189 of 329
  • CVE-2022-23681HigSep 6, 2022
    risk 0.51cvss 7.8epss 0.01

    Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete switch compromise in…

  • CVE-2022-38511HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.

  • CVE-2022-37083HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisCfg.

  • CVE-2022-37082HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyncWithHost.

  • CVE-2022-37081HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.

  • CVE-2022-37079HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-36455HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

  • CVE-2022-37076HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-36487HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36486HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-36485HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-36481HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.

  • CVE-2022-36479HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

  • CVE-2022-36461HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-36460HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-36459HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

  • CVE-2022-36458HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36456HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

  • CVE-2021-36667HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.03

    Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.

  • CVE-2022-26532HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.05

    A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through…