VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 56 of 324
  • CVE-2022-34596CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

  • CVE-2022-34595CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.

  • CVE-2022-33329CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.04

    Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…

  • CVE-2022-33328CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.04

    Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…

  • CVE-2022-33327CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.04

    Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…

  • CVE-2022-33326CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.04

    Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…

  • CVE-2022-33325CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.04

    Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…

  • CVE-2022-33314CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.04

    Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…

  • CVE-2022-33313CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.04

    Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…

  • CVE-2022-33312CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.04

    Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these…

  • CVE-2022-32092CriJun 27, 2022
    risk 0.64cvss 9.8epss 0.06

    D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi.

  • CVE-2022-31767CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.05

    IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 227980.

  • CVE-2022-26147CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.03

    The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

  • CVE-2022-31795CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and…

  • CVE-2022-31794CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such…

  • CVE-2022-30329CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attacker with valid credentials to execute arbitrary shell commands.

  • CVE-2022-31311CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request.

  • CVE-2022-30311CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command…

  • CVE-2022-30310CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command…

  • CVE-2022-30309CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control…