VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 7 of 324
  • CVE-2017-6360CriMar 23, 2017
    risk 0.72cvss 9.8epss 0.66

    QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.

  • CVE-2024-40891HigKEVFeb 4, 2025
    risk 0.71cvss 8.8epss 0.22

    **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on…

  • CVE-2024-40890HigKEVFeb 4, 2025
    risk 0.71cvss 8.8epss 0.22

    **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected…

  • CVE-2024-29973CriJun 4, 2024
    risk 0.71cvss 9.8epss 0.86

    ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating…

  • CVE-2024-29972CriJun 4, 2024
    risk 0.71cvss 9.8epss 0.89

    ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some…

  • CVE-2024-23108CriFeb 5, 2024
    risk 0.71cvss 10.0epss 0.78

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

  • CVE-2022-2185CriJul 1, 2022
    risk 0.71cvss 9.9epss 0.77

    A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code…

  • CVE-2021-3781CriFeb 16, 2022
    risk 0.71cvss 9.9epss 0.84

    A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript…

  • CVE-2021-37344CriAug 13, 2021
    risk 0.71cvss 9.8epss 0.97

    Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).

  • CVE-2020-15922CriJul 24, 2020
    risk 0.71cvss 9.8epss 0.57

    There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.

  • CVE-2020-9377HigKEVJul 9, 2020
    risk 0.71cvss 8.8epss 0.21

    D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2013-2568CriJan 29, 2020
    risk 0.71cvss 9.8epss 0.49

    A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.

  • CVE-2019-5029CriNov 13, 2019
    risk 0.71cvss 9.8epss 0.57

    An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches…

  • CVE-2019-14931CriOct 28, 2019
    risk 0.71cvss 9.8epss 0.58

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user…

  • CVE-2018-5347CriJan 12, 2018
    risk 0.71cvss 9.8epss 0.54

    Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.

  • CVE-2017-6361CriMar 23, 2017
    risk 0.71cvss 9.8epss 0.57

    QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2026-73570HigKEVAug 13, 2026
    risk 0.70cvss 8.9epss 0.01

    A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an…

  • CVE-2026-25108HigKEVFeb 13, 2026
    risk 0.70cvss 8.8epss 0.05

    FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

  • CVE-2025-34030CriJun 20, 2025
    risk 0.70cvss epss 0.60

    An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can inject shell commands by…

  • CVE-2025-0107CriJan 11, 2025
    risk 0.70cvss 9.8epss 0.79

    An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API…