VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 54 of 324
  • CVE-2022-44249CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.

  • CVE-2022-44808CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the…

  • CVE-2022-44201CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

  • CVE-2022-40741CriOct 31, 2022
    risk 0.64cvss 9.8epss 0.01

    Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to perform arbitrary system command and disrupt service.

  • CVE-2022-37915CriOct 28, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability could allow an attacker to execute…

  • CVE-2022-33189CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability.

  • CVE-2022-33150CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-32773CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this…

  • CVE-2022-32765CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this…

  • CVE-2022-30541CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this…

  • CVE-2022-29851CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.

  • CVE-2022-29520CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send an XML payload to trigger this vulnerability.

  • CVE-2022-29472CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.05

    An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request…

  • CVE-2022-27804CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request…

  • CVE-2022-43184CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.

  • CVE-2022-33874CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.03

    An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute…

  • CVE-2022-33872CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.03

    An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute…

  • CVE-2022-41525CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.

  • CVE-2022-41518CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.

  • CVE-2022-40475CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.