VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 40 of 324
  • CVE-2025-34099CriJul 10, 2025
    risk 0.64cvss epss 0.01

    An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php component when password encryption is enabled (a non-default configuration). The application improperly passes the HTTP Basic…

  • CVE-2025-34095CriJul 10, 2025
    risk 0.64cvss epss 0.04

    An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples/save.lsp endpoint. An unauthenticated attacker can send a crafted PUT request containing arbitrary Lua os.execute() code, which…

  • CVE-2025-48501CriJul 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.

  • CVE-2025-34082CriJul 3, 2025
    risk 0.64cvss epss 0.05

    A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Shadow services. The flaw arises due to improper input sanitization in the handling of specially crafted PROXYCMD commands on TCP ports 30022 and 5900. An…

  • CVE-2025-48890CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS…

  • CVE-2025-43879CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the telnet function. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS…

  • CVE-2025-6559CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.02

    Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended.

  • CVE-2025-25038CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.05

    An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this…

  • CVE-2025-44635CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.01

    There are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG2-1350W, NR1200W series routers before ERG2AW-MNW100-R1117; H3C ER3100G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2, ER6300G2, ER8300G2, ER8300G2-X series routers…

  • CVE-2025-41663CriJun 11, 2025
    risk 0.64cvss 9.8epss 0.01

    For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers, which are then executed with elevated privileges. To get into such a position, clients would need to use insecure…

  • CVE-2025-44882CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2025-44880CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2025-32002CriMay 15, 2025
    risk 0.64cvss 9.8epss 0.02

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier when 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker…

  • CVE-2025-45858CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.11

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.

  • CVE-2025-45491CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

  • CVE-2025-45042CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

  • CVE-2025-28039CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

  • CVE-2025-28038CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

  • CVE-2025-28036CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

  • CVE-2025-28035CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.