7 vulnerabilities classified as CWE-141 (参数分隔符转义处理不恰当). AI Chinese analysis included.
CWE-141 represents a critical input validation weakness where software fails to properly sanitize special characters that function as delimiters for parameters or arguments. This vulnerability typically arises when an application accepts unsanitized user input and passes it directly to a downstream component, such as a command interpreter or database query engine. Attackers exploit this flaw by injecting malicious delimiters, effectively breaking the intended structure of the input string. This manipulation can cause the downstream process to interpret injected data as executable commands or distinct arguments, leading to unauthorized actions, data leakage, or system compromise. To mitigate this risk, developers must rigorously validate and escape all incoming data, ensuring that delimiter characters are neutralized or strictly controlled before processing. Implementing allow-lists and using parameterized queries further reduces the attack surface by preventing unintended interpretation of special characters.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-20338 | Cisco IOS XE 安全漏洞 — Cisco IOS XE Software | 6.0 | Medium | 2025-09-24 |
| CVE-2025-31329 | Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform — SAP NetWeaver Application Server ABAP and ABAP Platform | 6.2 | Medium | 2025-05-13 |
| CVE-2024-0840 | Grandstream UCM Series IP PBX HTTP Parameter Injection — UCM Series | 8.8 | High | 2024-04-29 |
| CVE-2022-41665 | Siemens SICAM P850 和SICAM P855 安全漏洞 — SICAM P850 | 9.8 | Critical | 2022-10-11 |
| CVE-2022-29873 | Siemens SICAM 安全漏洞 — SICAM T | 9.8 | Critical | 2022-05-10 |
| CVE-2022-29872 | Siemens SICAM 输入验证错误漏洞 — SICAM T | 8.8 | High | 2022-05-10 |
| CVE-2020-7868 | Helpu remote code execution vulnerability — helpu.ocx | 9.6 | Critical | 2021-06-29 |
Vulnerabilities classified as CWE-141 (参数分隔符转义处理不恰当) represent 7 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.