VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 53 of 324
  • CVE-2022-46538CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.

  • CVE-2022-46634CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.

  • CVE-2022-46631CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.

  • CVE-2022-45005CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.05

    IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.

  • CVE-2022-37897CriDec 12, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the…

  • CVE-2022-45145CriDec 10, 2022
    risk 0.64cvss 9.8epss 0.01

    egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.

  • CVE-2022-33186CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying…

  • CVE-2022-45506CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.

  • CVE-2022-45497CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.

  • CVE-2022-45026CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export process.

  • CVE-2022-42496CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.

  • CVE-2022-44930CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

  • CVE-2022-44928CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

  • CVE-2022-43325CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.

  • CVE-2022-4221CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.05

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.

  • CVE-2022-44844CriNov 25, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.

  • CVE-2022-44843CriNov 25, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.

  • CVE-2022-44252CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.

  • CVE-2022-44251CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

  • CVE-2022-44250CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.