VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 6 of 324
  • CVE-2020-35665CriDec 23, 2020
    risk 0.73cvss 9.8epss 0.78

    An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.

  • CVE-2020-4006CriKEVNov 23, 2020
    risk 0.73cvss 9.1epss 0.17

    VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

  • CVE-2020-11978HigKEVJul 17, 2020
    risk 0.73cvss 8.8epss 0.99

    An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow…

  • CVE-2020-10879CriMar 23, 2020
    risk 0.73cvss 9.8epss 0.84

    rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.

  • CVE-2019-20500HigKEVMar 5, 2020
    risk 0.73cvss 7.8epss 0.97

    D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

  • CVE-2019-20215CriJan 29, 2020
    risk 0.73cvss 9.8epss 0.75

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled. The value of the urn: service/device is checked with the strstr function, which…

  • CVE-2020-7980CriJan 25, 2020
    risk 0.73cvss 9.8epss 0.83

    Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.

  • CVE-2019-5485CriSep 13, 2019
    risk 0.73cvss 10.0epss 0.60

    NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

  • CVE-2018-16167CriJan 9, 2019
    risk 0.73cvss 9.8epss 0.75

    LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-10660CriJun 26, 2018
    risk 0.73cvss 9.8epss 0.82

    An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

  • CVE-2017-17105CriDec 19, 2017
    risk 0.73cvss 9.8epss 0.85

    Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="15042…

  • CVE-2025-8943CriAug 14, 2025
    risk 0.72cvss 9.8epss 0.72

    The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise…

  • CVE-2024-51568CriOct 29, 2024
    risk 0.72cvss 10.0epss 0.45

    CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

  • CVE-2023-39780HigKEVSep 11, 2023
    risk 0.72cvss 8.8epss 0.34

    On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see…

  • CVE-2021-4039CriMar 1, 2022
    risk 0.72cvss 9.8epss 0.71

    A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.

  • CVE-2021-42071CriOct 7, 2021
    risk 0.72cvss 9.8epss 0.70

    In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.

  • CVE-2020-17456CriAug 20, 2020
    risk 0.72cvss 9.8epss 0.74

    SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.

  • CVE-2019-12780CriJun 10, 2019
    risk 0.72cvss 9.8epss 0.72

    The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.

  • CVE-2017-18369CriMay 2, 2019
    risk 0.72cvss 9.8epss 0.68

    The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through…

  • CVE-2018-20434CriApr 24, 2019
    risk 0.72cvss 9.8epss 0.71

    LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request…