VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 46 of 324
  • CVE-2024-26260CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.02

    The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without…

  • CVE-2024-24091CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.

  • CVE-2024-24333CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.

  • CVE-2024-24332CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.

  • CVE-2024-24331CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.

  • CVE-2024-24330CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.

  • CVE-2024-24329CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.

  • CVE-2024-24328CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.

  • CVE-2024-24327CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.

  • CVE-2024-24326CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.

  • CVE-2024-24325CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.

  • CVE-2023-38323CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

  • CVE-2023-38319CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

  • CVE-2023-38318CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

  • CVE-2023-38317CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

  • CVE-2023-52026CriJan 12, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface

  • CVE-2024-23061CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.

  • CVE-2024-23060CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg function.

  • CVE-2024-23059CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnsCfg function.

  • CVE-2024-23058CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.