VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 84 of 327
  • CVE-2025-54133CriAug 2, 2025
    risk 0.62cvss 9.6epss 0.00

    Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's MCP (Model Context Protocol) deeplink handler, allowing attackers to execute 2-click arbitrary system commands through social…

  • CVE-2025-6514CriJul 9, 2025
    risk 0.62cvss 9.6epss 0.78

    mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL

  • CVE-2025-48047CriMay 29, 2025
    risk 0.62cvss epss 0.14

    An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.

  • CVE-2025-43562CriMay 13, 2025
    risk 0.62cvss 9.1epss 0.45

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A…

  • CVE-2023-29120CriNov 5, 2024
    risk 0.62cvss 9.6epss 0.00

    Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.

  • CVE-2023-39367CriApr 17, 2024
    risk 0.62cvss 9.1epss 0.38

    An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2023-37928HigNov 30, 2023
    risk 0.62cvss 8.8epss 0.60

    A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted…

  • CVE-2023-37569HigAug 8, 2023
    risk 0.62cvss 8.8epss 0.34

    This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could…

  • CVE-2021-32692CriDec 23, 2022
    risk 0.62cvss 9.6epss 0.01

    Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by having the user visiting a website with the…

  • CVE-2021-44827HigMar 4, 2022
    risk 0.62cvss 8.8epss 0.54

    There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges.

  • CVE-2020-8105CriDec 20, 2021
    risk 0.62cvss 9.6epss 0.01

    OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.0.2.23_6.9V_dev_t2_homekit_RF_2.0.19_s2_k…

  • CVE-2021-3577HigNov 12, 2021
    risk 0.62cvss 8.8epss 0.60

    An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.

  • CVE-2021-27273HigMar 29, 2021
    risk 0.62cvss 8.8epss 0.65

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2020-36243HigFeb 7, 2021
    risk 0.62cvss 8.8epss 0.64

    The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.

  • CVE-2020-35606HigDec 21, 2020
    risk 0.62cvss 8.8epss 0.28

    Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.

  • CVE-2020-13448HigJun 1, 2020
    risk 0.62cvss 8.8epss 0.17

    QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

  • CVE-2013-1598HigJan 24, 2020
    risk 0.62cvss 8.8epss 0.20

    A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code.

  • CVE-2017-12945HigNov 27, 2019
    risk 0.62cvss 8.8epss 0.17

    Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute arbitrary commands as root.

  • CVE-2019-18873CriNov 12, 2019
    risk 0.62cvss 9.0epss 0.08

    FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control…

  • CVE-2018-18852HigJun 18, 2019
    risk 0.62cvss 8.8epss 0.61

    Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.