VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 41 of 324
  • CVE-2025-28037CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.

  • CVE-2025-28034CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the…

  • CVE-2025-29043CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.02

    An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234

  • CVE-2025-29042CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.02

    An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c

  • CVE-2025-29041CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c

  • CVE-2025-29040CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c

  • CVE-2025-27797CriApr 9, 2025
    risk 0.64cvss 9.8epss 0.01

    OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to the product.

  • CVE-2025-3363CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2025-3362CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2025-3361CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2025-26817CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.02

    Netwrix Password Secure 9.2.0.32454 allows OS command injection.

  • CVE-2025-28256CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

  • CVE-2025-22398CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.02

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command…

  • CVE-2025-28138CriMar 27, 2025
    risk 0.64cvss 9.8epss 0.01

    The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

  • CVE-2024-9053CriMar 20, 2025
    risk 0.64cvss 9.8epss 0.01

    vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which directly uses cloudpickle.loads() on received messages without any sanitization.…

  • CVE-2024-50390CriMar 7, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

  • CVE-2025-1265CriFeb 20, 2025
    risk 0.64cvss 9.9epss 0.01

    An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code execution on affected system.

  • CVE-2025-26613CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.03

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the WeGIA application, `gerenciar_backup.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code…

  • CVE-2021-46686CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ver.4.0.3 and earlier and acmailer DB ver.1.1.5 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker.

  • CVE-2025-25067CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.02

    mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.