VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 59 of 324
  • CVE-2022-28571CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.06

    D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.

  • CVE-2022-29080CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.02

    The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.

  • CVE-2022-27276CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27275CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27274CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27273CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27272CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27271CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27270CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27269CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.04

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27268CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.04

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet.

  • CVE-2022-23900CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

  • CVE-2021-32974CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands.

  • CVE-2021-46007CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.03

    totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.

  • CVE-2022-26290CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.

  • CVE-2022-26289CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.

  • CVE-2022-25441CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.05

    Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function.

  • CVE-2022-25438CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.05

    Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.

  • CVE-2021-45966CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to execute arbitrary code via shell metacharacters.

  • CVE-2022-22273CriMar 17, 2022
    risk 0.64cvss 9.8epss 0.02

    Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x,…