CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,475)
page 55 of 324| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-40929 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2022 | XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users). | ||
| CVE-2022-28811 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands. | ||
| CVE-2022-38826 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi. | ||
| CVE-2022-39815 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system. | ||
| CVE-2022-33941 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2022 | PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected… | ||
| CVE-2022-36566 | Cri | 0.64 | 9.8 | 0.02 | Aug 31, 2022 | Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function. | ||
| CVE-2022-36749 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2022 | RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file. | ||
| CVE-2022-37149 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2022 | WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter. | ||
| CVE-2022-37810 | Cri | 0.64 | 9.8 | 0.02 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac. | ||
| CVE-2021-42232 | Cri | 0.64 | 9.8 | 0.04 | Aug 23, 2022 | TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on… | ||
| CVE-2022-36273 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2022 | Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg. | ||
| CVE-2022-22140 | Cri | 0.64 | 9.8 | 0.04 | Aug 5, 2022 | An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability. | ||
| CVE-2022-21178 | Cri | 0.64 | 9.8 | 0.04 | Aug 5, 2022 | An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this… | ||
| CVE-2022-24405 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | ||
| CVE-2022-23100 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). | ||
| CVE-2020-28447 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2022 | This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath) | ||
| CVE-2022-28375 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2022 | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metacharacters into… | ||
| CVE-2022-28373 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2022 | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of the crtcrpc JSON listener in /usr/lib/lua/luci/crtc.lua. A remote attacker on the local network can inject shell metacharacters to… | ||
| CVE-2022-28888 | Cri | 0.64 | 9.8 | 0.04 | Jul 13, 2022 | Spryker Commerce OS 1.4.2 allows Remote Command Execution. | ||
| CVE-2022-34597 | Cri | 0.64 | 9.8 | 0.02 | Jul 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting. |
- risk 0.64cvss 9.8epss 0.01
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
- risk 0.64cvss 9.8epss 0.01
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.
- risk 0.64cvss 9.8epss 0.01
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.
- risk 0.64cvss 9.8epss 0.02
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.
- risk 0.64cvss 9.8epss 0.02
PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected…
- risk 0.64cvss 9.8epss 0.02
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
- risk 0.64cvss 9.8epss 0.03
RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.
- risk 0.64cvss 9.8epss 0.03
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.
- risk 0.64cvss 9.8epss 0.02
Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
- risk 0.64cvss 9.8epss 0.04
TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on…
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.
- risk 0.64cvss 9.8epss 0.04
An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.04
An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this…
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
- risk 0.64cvss 9.8epss 0.01
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)
- risk 0.64cvss 9.8epss 0.02
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metacharacters into…
- risk 0.64cvss 9.8epss 0.02
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of the crtcrpc JSON listener in /usr/lib/lua/luci/crtc.lua. A remote attacker on the local network can inject shell metacharacters to…
- risk 0.64cvss 9.8epss 0.04
Spryker Commerce OS 1.4.2 allows Remote Command Execution.
- risk 0.64cvss 9.8epss 0.02
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.