VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 20 of 324
  • CVE-2023-3991CriOct 16, 2023
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2023-34993CriOct 10, 2023
    risk 0.65cvss 9.8epss 0.18

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

  • CVE-2023-3572CriAug 8, 2023
    risk 0.65cvss 10.0epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.

  • CVE-2023-29778CriMay 2, 2023
    risk 0.65cvss 9.8epss 0.16

    GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

  • CVE-2023-2131CriApr 20, 2023
    risk 0.65cvss 10.0epss 0.02

    Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2023-27394CriMar 28, 2023
    risk 0.65cvss 9.8epss 0.18

    Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.

  • CVE-2022-2024CriFeb 25, 2023
    risk 0.65cvss 9.8epss 0.98

    OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

  • CVE-2022-44149HigJan 6, 2023
    risk 0.65cvss 8.8epss 0.64

    The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required

  • CVE-2022-45711CriDec 23, 2022
    risk 0.65cvss 9.8epss 0.20

    IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.

  • CVE-2022-40624CriDec 20, 2022
    risk 0.65cvss 9.8epss 0.17

    pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

  • CVE-2022-33207CriOct 25, 2022
    risk 0.65cvss 9.9epss 0.04

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2022-33206CriOct 25, 2022
    risk 0.65cvss 9.9epss 0.04

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2022-33205CriOct 25, 2022
    risk 0.65cvss 9.9epss 0.04

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2022-33204CriOct 25, 2022
    risk 0.65cvss 9.9epss 0.04

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2022-33195CriOct 25, 2022
    risk 0.65cvss 10.0epss 0.03

    Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these…

  • CVE-2022-33194CriOct 25, 2022
    risk 0.65cvss 10.0epss 0.03

    Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these…

  • CVE-2022-33193CriOct 25, 2022
    risk 0.65cvss 10.0epss 0.03

    Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these…

  • CVE-2022-33192CriOct 25, 2022
    risk 0.65cvss 10.0epss 0.03

    Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these…

  • CVE-2022-38828CriSep 16, 2022
    risk 0.65cvss 9.8epss 0.19

    TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi

  • CVE-2022-38308CriSep 14, 2022
    risk 0.65cvss 9.8epss 0.20

    TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.