CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,142
Total CVEs
441
Critical
479
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 78
3 Netgear 72
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 18
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,142)

CVE-2025-59818
10.0

This vulnerability allows authenticated attackers to execute arbitrary system commands by manipulating uploaded file names. It affects Zenitel communi...

Feb 4, 2026
CVE-2025-64090
10.0

This vulnerability allows authenticated attackers to execute arbitrary commands on affected devices by manipulating the hostname parameter. It affects...

Jan 9, 2026
CVE-2025-64093
10.0

This is a critical remote code execution vulnerability in Zenitel devices that allows unauthenticated attackers to execute arbitrary commands by injec...

Jan 9, 2026
CVE-2025-61492
10.0

A command injection vulnerability in terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary system commands by providing malicious input ...

Jan 7, 2026
CVE-2025-10035
KEV EPSS 66% 10.0

A critical deserialization vulnerability in Fortra's GoAnywhere MFT License Servlet allows attackers with forged license signatures to execute arbitra...

Sep 18, 2025
CVE-2024-48841
10.0

This critical vulnerability in FLXEON software allows remote attackers to execute arbitrary code with elevated privileges through network access. It a...

Jan 27, 2025
CVE-2024-39760
10.0

This critical vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on Wavlink AC3000 routers by sending speci...

Jan 14, 2025
CVE-2024-20418
10.0

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on Cisco URWB Access Points by ...

Nov 6, 2024
CVE-2024-43693
10.0

This vulnerability allows remote attackers to execute arbitrary commands on ProGauge MAGLINK LX CONSOLE UTILITY systems by sending specially crafted P...

Sep 25, 2024
CVE-2024-29895
10.0

CVE-2024-29895 is a critical command injection vulnerability in Cacti's 1.3.x DEV branch that allows unauthenticated attackers to execute arbitrary co...

May 14, 2024
CVE-2024-28354
10.0

This is a critical command injection vulnerability in TRENDnet TEW-827DRU routers that allows remote attackers to execute arbitrary commands with root...

Mar 15, 2024
CVE-2022-31161
10.0

CVE-2022-31161 is a critical remote code execution vulnerability in Roxy-WI web interface versions prior to 6.1.1.0. It allows unauthenticated attacke...

Jul 15, 2022
CVE-2021-32933
10.0

This vulnerability allows attackers to upload malicious files through an API in MDT AutoSave software, which can manipulate process creation commands ...

Apr 1, 2022
CVE-2021-45630
10.0

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects multiple NETGEAR...

Dec 26, 2021
CVE-2021-27447
10.0

Mesa Labs AmegaView version 3.0 contains a command injection vulnerability (CWE-77) that allows remote attackers to execute arbitrary code on affected...

Dec 21, 2021
CVE-2026-22688
9.9

CVE-2026-22688 is a command injection vulnerability in WeKnora that allows authenticated users to inject malicious commands into MCP stdio settings, c...

Jan 10, 2026
CVE-2025-58428
9.9

This critical vulnerability in TLS4B ATG systems allows authenticated remote attackers to execute arbitrary system commands on the underlying Linux op...

Oct 23, 2025
CVE-2025-34267
9.9

Flowise versions 3.0.1 through 3.0.7 and all later versions with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerabil...

Oct 14, 2025
CVE-2025-22630
9.9

This CVE describes a command injection vulnerability in the WordPress Widget Options plugin that allows attackers to execute arbitrary operating syste...

Feb 14, 2025
CVE-2024-20432
9.9

An authenticated low-privileged attacker can execute arbitrary CLI commands with network-admin privileges on Cisco NDFC-managed devices via command in...

Oct 2, 2024
CVE-2023-25911
9.9

CVE-2023-25911 is a critical OS command injection vulnerability in Danfoss AK-EM100 web applications that allows authenticated attackers to execute ar...

Jun 11, 2023
CVE-2023-27407
9.9

CVE-2023-27407 is a command injection vulnerability in SCALANCE LPE9403 industrial network devices that allows authenticated remote attackers to execu...

May 9, 2023
CVE-2021-34809
9.9

This is a command injection vulnerability in Synology Download Station that allows authenticated remote attackers to execute arbitrary commands on the...

Jun 18, 2021
CVE-2026-3485
9.8

This CVE describes a remote command injection vulnerability in D-Link DIR-868L routers via the SSDP service. Attackers can execute arbitrary operating...

Mar 3, 2026
CVE-2026-2686
9.8

This CVE describes a remote command injection vulnerability in SECCN Dingcheng G10 software version 3.1.0.181203. Attackers can execute arbitrary oper...

Feb 19, 2026
CVE-2026-24132
9.8

Orval versions 7.19.0 and below and 8.0.0-rc.0 through 8.0.2 contain a code injection vulnerability where untrusted OpenAPI specifications can inject ...

Jan 23, 2026
CVE-2026-23947
9.8

Orval versions 7.19.0 through 8.0.2 contain a code injection vulnerability in the x-enumDescriptions field processing. Untrusted OpenAPI specification...

Jan 20, 2026
CVE-2025-60021
9.8

This CVE describes a remote command injection vulnerability in Apache bRPC's heap profiler service. Attackers can execute arbitrary commands by inject...

Jan 16, 2026
CVE-2025-69542
9.8

A command injection vulnerability in D-Link DIR895LA1 routers allows attackers to execute arbitrary commands with root privileges by sending malicious...

Jan 9, 2026
CVE-2025-70161
9.8

EDIMAX BR-6208AC V2 router firmware version 1.02 contains a command injection vulnerability in the pppUserName field that allows attackers to execute ...

Jan 9, 2026
CVE-2025-15471
9.8

This CVE describes a remote command injection vulnerability in TRENDnet TEW-713RE routers. Attackers can execute arbitrary operating system commands b...

Jan 7, 2026
CVE-2025-69201
9.8

CVE-2025-69201 is a command injection vulnerability in Tugtainer's agent API that allows attackers to inject arbitrary arguments into docker container...

Dec 29, 2025
CVE-2025-67728
9.8

CVE-2025-67728 is a command injection vulnerability in Fireshare that allows authenticated users (or unauthenticated users if Public Uploads is enable...

Dec 12, 2025
CVE-2025-66032
9.8

CVE-2025-66032 is a command injection vulnerability in Claude Code that allows bypassing read-only validation to execute arbitrary code. Attackers can...

Dec 3, 2025
CVE-2025-60854
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link R15 (AX1500) routers by manipulating the model name parameter durin...

Dec 2, 2025
CVE-2025-66219
9.8

CVE-2025-66219 is a command injection vulnerability in willitmerge, a command-line tool for checking pull request mergeability. Attackers can execute ...

Nov 29, 2025
CVE-2025-59741
9.8

This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows unauthenticated attackers to execute arbitrary operating syst...

Oct 2, 2025
CVE-2025-59735
9.8

This is a critical command injection vulnerability in AndSoft's e-TMS transportation management system. Attackers can execute arbitrary operating syst...

Oct 2, 2025
CVE-2025-59736
9.8

This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows attackers to execute arbitrary operating system commands on t...

Oct 2, 2025
CVE-2025-59737
9.8

This is a critical command injection vulnerability in AndSoft's e-TMS transportation management system. Attackers can execute arbitrary operating syst...

Oct 2, 2025
CVE-2025-59738
9.8

This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows unauthenticated attackers to execute arbitrary operating syst...

Oct 2, 2025
CVE-2025-59739
9.8

This is a critical command injection vulnerability in AndSoft's e-TMS transportation management software that allows unauthenticated attackers to exec...

Oct 2, 2025
CVE-2025-59740
9.8

This is a critical command injection vulnerability in AndSoft's e-TMS transportation management software that allows unauthenticated attackers to exec...

Oct 2, 2025
CVE-2025-61044
9.8

This CVE describes a command injection vulnerability in TOTOLINK X18 routers that allows attackers to execute arbitrary commands on the device. The vu...

Oct 1, 2025
CVE-2025-61045
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X18 routers by injecting malicious code into the mac parameter of...

Oct 1, 2025
CVE-2025-59834
9.8

CVE-2025-59834 is a command injection vulnerability in ADB MCP Server versions 0.1.0 and earlier that allows attackers to execute arbitrary commands o...

Sep 25, 2025
CVE-2025-52053
EPSS 67.3% 9.8

This is a critical command injection vulnerability in TOTOLINK X6000R routers that allows unauthenticated attackers to execute arbitrary commands on a...

Sep 15, 2025
CVE-2025-59046
9.8

CVE-2025-59046 is a command injection vulnerability in the interactive-git-checkout npm package that allows attackers to execute arbitrary commands on...

Sep 9, 2025
CVE-2025-57633
9.8

This CVE describes a critical command injection vulnerability in FTP-Flask-python that allows unauthenticated remote attackers to execute arbitrary op...

Sep 9, 2025
CVE-2025-57285
9.8

CVE-2025-57285 is a critical command injection vulnerability in codeceptjs 3.7.3 that allows attackers to execute arbitrary commands on the host syste...

Sep 8, 2025

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,142 CVEs classified as CWE-77, with 441 rated critical and 479 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free