VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 21 of 324
  • CVE-2022-37056CriAug 28, 2022
    risk 0.65cvss 9.8epss 0.10

    D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

  • CVE-2022-37070CriAug 25, 2022
    risk 0.65cvss 9.8epss 0.10

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.

  • CVE-2022-2314CriAug 15, 2022
    risk 0.65cvss 9.8epss 0.17

    The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

  • CVE-2022-29592CriMay 5, 2022
    risk 0.65cvss 9.8epss 0.20

    Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).

  • CVE-2022-28557CriMay 4, 2022
    risk 0.65cvss 9.8epss 0.23

    There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution

  • CVE-2021-32933CriApr 1, 2022
    risk 0.65cvss 10.0epss 0.01

    An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process.

  • CVE-2021-27476CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and…

  • CVE-2022-25082CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.16

    TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-23389CriFeb 14, 2022
    risk 0.65cvss 9.8epss 0.22

    PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.

  • CVE-2021-44453CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.

  • CVE-2021-43984CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-43981CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-23198CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-22657CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-21883CriDec 22, 2021
    risk 0.65cvss 9.9epss 0.06

    An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2021-21872CriDec 22, 2021
    risk 0.65cvss 9.9epss 0.06

    An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2021-21954CriDec 9, 2021
    risk 0.65cvss 9.9epss 0.02

    A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution.

  • CVE-2021-40113CriNov 4, 2021
    risk 0.65cvss 10.0epss 0.05

    Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if…

  • CVE-2020-25368CriNov 4, 2021
    risk 0.65cvss 9.8epss 0.09

    A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.

  • CVE-2020-25367CriNov 4, 2021
    risk 0.65cvss 9.8epss 0.09

    A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.