VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 47 of 324
  • CVE-2024-23057CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function.

  • CVE-2024-22942CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function.

  • CVE-2023-51984CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attackers to execute arbitrary commands via shell.

  • CVE-2023-52029CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg function.

  • CVE-2023-52028CriJan 11, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

  • CVE-2023-49235CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.

  • CVE-2023-50651CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.

  • CVE-2023-51100CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .

  • CVE-2023-51099CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .

  • CVE-2023-51098CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo .

  • CVE-2023-51094CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.

  • CVE-2023-51035CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.

  • CVE-2023-51033CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface.

  • CVE-2023-50147CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.

  • CVE-2023-51028CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtenderConfig interface of the cstecgi.cgi.

  • CVE-2023-50993CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Ruijie WS6008 v1.x v2.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 and WS6108 v1.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 was discovered to contain a command injection vulnerability via the function downFiles.

  • CVE-2021-42796CriDec 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.

  • CVE-2023-42495CriDec 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CVE-2023-47254CriDec 9, 2023
    risk 0.64cvss 9.8epss 0.02

    An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface.

  • CVE-2023-48800CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.