VYPR

CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

BaseDraft

Description

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-137 · CAPEC-174 · CAPEC-41 · CAPEC-460 · CAPEC-88

CVEs mapped to this weakness (466)

page 13 of 24
  • CVE-2026-1716HigMar 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.

  • CVE-2026-1715HigMar 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.

  • CVE-2025-67858HigJan 8, 2026
    risk 0.46cvss —epss 0.00

    A Improper Neutralization of Argument Delimiters vulnerability in Foomuuri can lead to integrity loss of the firewall configuration or further unspecified impact by manipulating the JSON configuration passed to `nft`. This issue affects Foomuuri: from ? before 0.31.

  • CVE-2025-35010HigJun 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNPINGTM command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters…

  • CVE-2025-35009HigJun 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNNETSP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters…

  • CVE-2025-35008HigJun 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MMNAME command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters…

  • CVE-2025-35007HigJun 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFRULE command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters…

  • CVE-2025-35006HigJun 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFPORTFWD command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument…

  • CVE-2025-35005HigJun 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFMAC command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in…

  • CVE-2025-35004HigJun 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFIP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in…

  • CVE-2024-51532HigDec 19, 2024
    risk 0.46cvss 7.1epss 0.00

    Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

  • CVE-2023-6634HigJan 11, 2024
    risk 0.46cvss 8.1epss 0.09

    The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated…

  • CVE-2022-25900HigJul 1, 2022
    risk 0.46cvss 8.1epss 0.04

    All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.

  • CVE-2022-25865HigMay 13, 2022
    risk 0.46cvss 8.1epss 0.07

    The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch…

  • CVE-2022-25866HigApr 25, 2022
    risk 0.46cvss 8.1epss 0.04

    The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that…

  • CVE-2022-25648HigApr 19, 2022
    risk 0.46cvss 8.1epss 0.05

    The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags…

  • CVE-2022-24066HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.04

    The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git…

  • CVE-2022-24440HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.03

    The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git…

  • CVE-2022-21235HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.02

    The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

  • CVE-2022-21187HigMar 14, 2022
    risk 0.46cvss 8.1epss 0.04

    The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_repo function (when using hg), the url parameter is passed to the hg clone command. By injecting some hg options it was possible to get arbitrary command…