VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 38 of 324
  • CVE-2025-10568CriSep 19, 2025
    risk 0.64cvss 9.8epss 0.00

    HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to address the potential vulnerability.

  • CVE-2025-23316CriSep 17, 2025
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by manipulating the model name parameter in the model control APIs. A successful exploit of this vulnerability might lead to…

  • CVE-2025-9972CriSep 17, 2025
    risk 0.64cvss 9.8epss 0.02

    Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device.

  • CVE-2025-34186CriSep 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Because the binary…

  • CVE-2025-34184CriSep 16, 2025
    risk 0.64cvss 9.8epss 0.03

    Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full…

  • CVE-2025-59041CriSep 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`. Prior to version 1.0.105, a maliciously configured user email in git could be used to trigger arbitrary code execution before a user accepted the…

  • CVE-2025-55048CriSep 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Multiple CWE-78

  • CVE-2025-54857CriSep 1, 2025
    risk 0.64cvss 9.8epss 0.03

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BASIC MB-A130 Ver.1.5.8 and earlier. If exploited, a remote unauthenticated attacker may execute arbitrary OS commands with root privileges.

  • CVE-2009-20010CriAug 30, 2025
    risk 0.64cvss epss 0.01

    Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail subsystem. The vulnerability arises from unsanitized user input passed via a POST request to the data parameter, which is processed by the underlying shell…

  • CVE-2024-46484CriAug 29, 2025
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.

  • CVE-2025-55583CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.06

    D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution…

  • CVE-2018-25115CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.10

    Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication.…

  • CVE-2025-3128CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete information in Mitsubishi Electric smartRTU, or cause a denial-of service condition on the product.

  • CVE-2010-20059CriAug 20, 2025
    risk 0.64cvss epss 0.01

    FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.

  • CVE-2012-10059CriAug 13, 2025
    risk 0.64cvss epss 0.03

    Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands,…

  • CVE-2012-10040CriAug 11, 2025
    risk 0.64cvss epss 0.02

    Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, whose constructor in network.inc calls exec() with unsanitized input. An authenticated attacker can exploit this to execute…

  • CVE-2012-10039CriAug 11, 2025
    risk 0.64cvss epss 0.02

    ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell commands, resulting in…

  • CVE-2012-10037CriAug 11, 2025
    risk 0.64cvss epss 0.01

    PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands, leading to code execution under the web server's…

  • CVE-2012-10046CriAug 8, 2025
    risk 0.64cvss epss 0.03

    The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-msg.cgi script. The CGI handler fails to sanitize user-supplied input passed via the id parameter, allowing attackers to inject…

  • CVE-2012-10041CriAug 8, 2025
    risk 0.64cvss epss 0.03

    WAN Emulator v2.3 contains two unauthenticated command execution vulnerabilities. The result.php script calls shell_exec() with unsanitized input from the pc POST parameter, allowing remote attackers to execute arbitrary commands as the www-data user. The system also includes a…