CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

359 vulnerabilities with CWE-88
CVE-2025-35010 HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 - Authenticated Command Injection via AT+MNPINGTM
CVSS 7.1
CVE-2025-35009 HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware - Authenticated Command Injection via AT+MNNETSP
CVSS 7.1
CVE-2025-35008 HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware < 1.2.0-r1132 - Authenticated Command Injection via AT+MMNAME
CVSS 7.1
CVE-2025-35007 HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware - Authenticated Command Injection via AT+MFRULE
CVSS 7.1
CVE-2025-35006 HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware - Authenticated Command Injection via AT+MFPORTFWD
CVSS 7.1
CVE-2025-35005 HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware - Authenticated Command Injection via AT+MFMAC
CVSS 7.1
CVE-2025-35004 HIGH
Microhard BulletLTE-NA2 and IPn4Gii-NA2 Firmware < 1.2.0-r1132 - Authenticated Command Injection via AT+MFIP
CVSS 7.1
CVE-2025-32459 HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh sync_time Argument
CVSS 7.7
CVE-2025-32458 HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh get_syslog_from_qtn Argument
CVSS 7.7
CVE-2025-32457 HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh get_file_from_qtn Argument
CVSS 7.7
CVE-2025-32456 HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh put_file_to_qtn Argument
CVSS 7.7
CVE-2025-32455 HIGH
onsemi Quantenna Wi-Fi Firmware - OS Command Injection via router_command.sh run_cmd Argument
CVSS 7.7
CVE-2025-49008 CRITICAL
Atheos < 6.0.4 - OS Command Injection via Execute.php Argument Injection
CVE-2025-3945 HIGH
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Command Injection
CVSS 7.2
CVE-2025-1712 HIGH
Checkmk <2.4.0p1,<2.3.0p32,<2.2.0p42,2.1.0 - Command Injection
CVSS 8.8
CVE-2025-31499 HIGH
jellyfin < 10.10.7 - Authenticated Argument Injection in FFmpeg via Stream Endpoints
CVSS 8.8
CVE-2025-32931 CRITICAL
DevDojo Voyager <1.8.0 - Command Injection
CVSS 9.1
CVE-2025-29768 MEDIUM
Vim < 9.1.1198 - Data Loss via Crafted Zip File in zip.vim
CVSS 4.4
CVE-2025-27146 LOW
matrix-appservice-irc <3.0.3 - Command Injection
CVSS 2.7
CVE-2025-24845 MEDIUM
Defense Platform Home Edition <3.9.51.x - Command Injection
CVSS 5.5
CVE-2025-0065 HIGH
TeamViewer <15.62 - Privilege Escalation
CVSS 7.8
CVE-2025-23073 LOW
Wikimedia Foundation Mediawiki - GlobalBlocking Extension - Info Di...
CVSS 3.5
CVE-2025-21613 CRITICAL
go-git < 5.13.0 - Argument Injection via File Transport Protocol
CVSS 9.8
CVE-2024-58275 HIGH
Easywall 0.3.1 - Authenticated Remote Command Execution via Ports-Save Endpoint
CVE-2024-47516 CRITICAL
Pagure Repository History - Git Argument Injection Code Execution
CVSS 9.8
Details
Vulnerabilities 359