CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,475)
page 53 of 324| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46538 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2022 | Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac. | ||
| CVE-2022-46634 | Cri | 0.64 | 9.8 | 0.02 | Dec 15, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function. | ||
| CVE-2022-46631 | Cri | 0.64 | 9.8 | 0.02 | Dec 15, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function. | ||
| CVE-2022-45005 | Cri | 0.64 | 9.8 | 0.05 | Dec 13, 2022 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function. | ||
| CVE-2022-37897 | Cri | 0.64 | 9.8 | 0.02 | Dec 12, 2022 | There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the… | ||
| CVE-2022-45145 | Cri | 0.64 | 9.8 | 0.01 | Dec 10, 2022 | egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file. | ||
| CVE-2022-33186 | Cri | 0.64 | 9.8 | 0.02 | Dec 8, 2022 | A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying… | ||
| CVE-2022-45506 | Cri | 0.64 | 9.8 | 0.02 | Dec 8, 2022 | Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName. | ||
| CVE-2022-45497 | Cri | 0.64 | 9.8 | 0.02 | Dec 8, 2022 | Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand. | ||
| CVE-2022-45026 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2022 | An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export process. | ||
| CVE-2022-42496 | Cri | 0.64 | 9.8 | 0.02 | Dec 5, 2022 | OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product. | ||
| CVE-2022-44930 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2022 | D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function. | ||
| CVE-2022-44928 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2022 | D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function. | ||
| CVE-2022-43325 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2022 | An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input. | ||
| CVE-2022-4221 | Cri | 0.64 | 9.8 | 0.05 | Dec 1, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7. | ||
| CVE-2022-44844 | Cri | 0.64 | 9.8 | 0.02 | Nov 25, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function. | ||
| CVE-2022-44843 | Cri | 0.64 | 9.8 | 0.02 | Nov 25, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function. | ||
| CVE-2022-44252 | Cri | 0.64 | 9.8 | 0.02 | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function. | ||
| CVE-2022-44251 | Cri | 0.64 | 9.8 | 0.02 | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function. | ||
| CVE-2022-44250 | Cri | 0.64 | 9.8 | 0.02 | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function. |
- risk 0.64cvss 9.8epss 0.02
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.
- risk 0.64cvss 9.8epss 0.05
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.
- risk 0.64cvss 9.8epss 0.02
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the…
- risk 0.64cvss 9.8epss 0.01
egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.
- risk 0.64cvss 9.8epss 0.02
A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying…
- risk 0.64cvss 9.8epss 0.02
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
- risk 0.64cvss 9.8epss 0.02
Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.
- risk 0.64cvss 9.8epss 0.01
An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export process.
- risk 0.64cvss 9.8epss 0.02
OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.
- risk 0.64cvss 9.8epss 0.03
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
- risk 0.64cvss 9.8epss 0.03
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
- risk 0.64cvss 9.8epss 0.03
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
- risk 0.64cvss 9.8epss 0.05
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
- risk 0.64cvss 9.8epss 0.02
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.