VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 294 of 324
  • CVE-2022-20880MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20879MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20878MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20877MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20876MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20875MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20874MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20873MedJul 21, 2022
    risk 0.31cvss 4.7epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting…

  • CVE-2022-20801MedMay 4, 2022
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities…

  • CVE-2022-20799MedMay 4, 2022
    risk 0.31cvss 4.7epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities…

  • CVE-2022-20693MedApr 15, 2022
    risk 0.31cvss 4.7epss 0.02

    A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…

  • CVE-2021-22557MedOct 4, 2021
    risk 0.31cvss 5.3epss 0.02

    SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator. We recommend upgrading SLO Generator past https://github.com/google/slo-generator/pull/173

  • CVE-2020-26300MedSep 9, 2021
    risk 0.31cvss 5.9epss 0.01

    systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix.

  • CVE-2021-1538MedJun 4, 2021
    risk 0.31cvss 4.7epss 0.02

    A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This vulnerability is due to insufficient sanitization of configuration entries. An attacker could exploit…

  • CVE-2016-1141MedJan 30, 2016
    risk 0.31cvss 4.7epss 0.01

    KDDI HOME SPOT CUBE devices before 2 allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.

  • CVE-2026-46420MedJul 17, 2026
    risk 0.30cvss 5.6epss 0.02

    setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled files such as .php-version, composer.lock through…

  • CVE-2025-54941MedOct 30, 2025
    risk 0.30cvss 4.6epss 0.00

    An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or the example dag code…

  • CVE-2025-60013MedOct 15, 2025
    risk 0.30cvss 4.6epss 0.00

    When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit…

  • CVE-2025-9262MedAug 20, 2025
    risk 0.30cvss 5.6epss 0.05

    A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handler. This manipulation causes os command injection. The attack may be initiated remotely. The attack is considered to…

  • CVE-2025-1369MedFeb 17, 2025
    risk 0.30cvss 4.5epss 0.03

    A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerability is an unknown functionality of the component USB Password Handler. The manipulation leads to os command injection. The attack needs to be approached…