CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,157
Total CVEs
445
Critical
490
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,157)

CVE-2024-44572
8.8

RELY-PCIe versions v22.2.1 through v23.1.0 contain a command injection vulnerability in the sys_mgmt function that allows attackers to execute arbitra...

Sep 11, 2024
CVE-2024-44574
8.8

RELY-PCIe versions v22.2.1 through v23.1.0 contain a command injection vulnerability in the sys_conf function that allows attackers to execute arbitra...

Sep 11, 2024
CVE-2024-44577
8.8

RELY-PCIe versions 22.2.1 through 23.1.0 contain a command injection vulnerability in the time_date function. This allows attackers to execute arbitra...

Sep 11, 2024
CVE-2024-44334
8.8

This vulnerability allows remote attackers to execute arbitrary commands on affected D-Link routers due to insufficient input filtering in the upgrade...

Sep 9, 2024
CVE-2024-7029
8.8

CVE-2024-7029 is a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands on affected systems over the ne...

Aug 2, 2024
CVE-2024-39570
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands with root privileges on SINEMA Remote Connect Server by exploiting ins...

Jul 9, 2024
CVE-2024-35241
8.8

This vulnerability in Composer (PHP dependency manager) allows remote code execution when using certain commands with packages installed from git repo...

Jun 10, 2024
CVE-2024-37569
8.8

This CVE describes a command injection vulnerability in Mitel 6869i devices that allows authenticated attackers to execute arbitrary shell commands wi...

Jun 9, 2024
CVE-2024-35397
8.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CP900L routers by injecting malicious commands into the hostTime ...

May 28, 2024
CVE-2024-32281
8.8

Tenda AC7V1.0 routers running firmware version 15.03.06.44 contain a command injection vulnerability in the formexeCommand function via the cmdinput p...

Apr 17, 2024
CVE-2024-30220
8.8

A command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows attackers on the same network to execute arbitrary commands wit...

Apr 15, 2024
CVE-2024-30850
8.8

This vulnerability in tiagorlampert CHAOS v5.0.1 allows remote attackers to execute arbitrary code by exploiting the BuildClient function. Attackers c...

Apr 12, 2024
CVE-2024-29269
8.8

This vulnerability allows attackers to execute arbitrary system commands on Telesquare TLR-2005Ksh routers via the Cmd parameter. Attackers can gain f...

Apr 10, 2024
CVE-2024-28041
8.8

CVE-2024-28041 is a command injection vulnerability in HGW BL1500HM routers that allows network-adjacent unauthenticated attackers to execute arbitrar...

Mar 25, 2024
CVE-2024-29366
8.8

A command injection vulnerability in the cgibin binary of DIR-845L router firmware allows attackers to execute arbitrary commands with root privileges...

Mar 22, 2024
CVE-2024-25228
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on Vinchin Backup and Recovery systems via improper input validation in th...

Mar 14, 2024
CVE-2023-24330
8.8

This CVE describes a command injection vulnerability in D-Link DIR-882 routers that allows attackers to execute arbitrary commands via crafted POST re...

Feb 21, 2024
CVE-2023-40263
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on Atos Unify OpenScape Voice Trace Manager systems via FTP functional...

Feb 8, 2024
CVE-2024-22900
8.8

Vinchin Backup & Recovery v7.2 contains an authenticated remote code execution vulnerability in the setNetworkCardInfo function. This allows authentic...

Feb 2, 2024
CVE-2024-22903
8.8

Vinchin Backup & Recovery v7.2 contains an authenticated remote code execution vulnerability in the deleteUpdateAPK function. This allows authenticate...

Feb 2, 2024
CVE-2023-6940
8.8

CVE-2023-6940 is a command injection vulnerability in MLflow that allows attackers to execute arbitrary commands on the victim system by tricking user...

Dec 19, 2023
CVE-2023-47576
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on Relyum RELY-PCIe and RELY-REC devices through the web interface. At...

Dec 13, 2023
CVE-2023-49213
8.8

This vulnerability allows remote attackers to execute arbitrary commands on Ironman PowerShell Universal servers via crafted HTTP requests to API endp...

Nov 23, 2023
CVE-2023-38193
8.8

SuperWebMailer 9.00.0.01710 contains a command injection vulnerability in the sendmail functionality that allows remote attackers to execute arbitrary...

Oct 21, 2023
CVE-2023-45208
8.8

This vulnerability allows attackers within wireless range of the D-Link DAP-X1860 repeater to execute arbitrary shell commands as root during device s...

Oct 10, 2023
CVE-2023-44827
8.8

This vulnerability allows authenticated attackers to execute arbitrary code on ZenTao project management systems via crafted scripts in the Office Con...

Oct 10, 2023
CVE-2023-45355
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on the Atos Unify OpenScape 4000 Platform operating system, potentiall...

Oct 9, 2023
CVE-2023-45351
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on Atos Unify OpenScape 4000 systems via command injection in the AShb...

Oct 9, 2023
CVE-2023-43138
8.8

This CVE describes a command injection vulnerability in TPLINK TL-ER5120G routers where authenticated attackers can execute arbitrary commands by inje...

Sep 20, 2023
CVE-2023-33136
8.8

This vulnerability allows remote attackers to execute arbitrary code on Azure DevOps Server instances by exploiting improper input validation in comma...

Sep 12, 2023
CVE-2023-38829
8.8

This vulnerability allows remote attackers to execute arbitrary code on NETIS SYSTEMS WF2409E routers by exploiting improper input validation in the p...

Sep 11, 2023
CVE-2023-37469
8.8

CVE-2023-37469 is a command injection vulnerability in CasaOS personal cloud software that allows authenticated users to execute arbitrary commands by...

Aug 24, 2023
CVE-2023-23564
8.8

CVE-2023-23564 is a command injection vulnerability in Geomatika IsiGeo Web 6.0 that allows authenticated remote attackers to execute arbitrary comman...

Aug 22, 2023
CVE-2023-2910
8.8

This CVE describes a command injection vulnerability in ASUSTOR Data Master (ADM) printer service that allows remote unauthorized attackers to execute...

Aug 17, 2023
CVE-2023-3718
8.8

CVE-2023-3718 is an authenticated command injection vulnerability in Aruba AOS-CX switches that allows attackers with CLI access to execute arbitrary ...

Aug 1, 2023
CVE-2023-24519
8.8

This CVE describes two OS command injection vulnerabilities in the Milesight UR32L router's vtysh_ubus toolsh_excute functionality. Attackers can exec...

Jul 6, 2023
CVE-2023-24582
8.8

Two OS command injection vulnerabilities in Milesight UR32L routers allow remote attackers to execute arbitrary commands via specially crafted TCP pac...

Jul 6, 2023
CVE-2023-26297
8.8

CVE-2023-26297 is a command injection vulnerability in HP Device Manager that allows attackers to execute arbitrary commands on affected systems. This...

Jun 12, 2023
CVE-2023-35031
8.8

This vulnerability allows authenticated users to execute arbitrary commands on affected Atos Unify OpenScape 4000 systems through command injection. A...

Jun 12, 2023
CVE-2023-35033
8.8

This vulnerability allows authenticated users to execute arbitrary commands on Atos Unify OpenScape 4000 systems through command injection. It affects...

Jun 12, 2023
CVE-2023-34233
8.8

The Snowflake Connector for Python versions before 3.0.2 are vulnerable to command injection through SSO browser URL authentication. An attacker can s...

Jun 8, 2023
CVE-2023-34231
8.8

The gosnowflake Golang driver prior to version 1.6.19 contains a command injection vulnerability in SSO browser URL authentication. An attacker who tr...

Jun 8, 2023
CVE-2023-33538
8.8

This CVE describes a command injection vulnerability in specific TP-Link router models that allows authenticated attackers to execute arbitrary comman...

Jun 7, 2023
CVE-2023-33782
8.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-842V2 routers via the iperf3 diagnostics function. Attackers ca...

Jun 7, 2023
CVE-2023-33530
8.8

This CVE describes a command injection vulnerability in Tenda G103 Gigabit GPON Terminal devices. Attackers with web management access can execute arb...

Jun 6, 2023
CVE-2023-33722
8.8

EDIMAX BR-6288ACL router firmware version 1.12 contains an authenticated remote code execution vulnerability in the pppUserName parameter. Attackers w...

May 31, 2023
CVE-2023-31996
8.8

This vulnerability allows remote attackers to execute arbitrary commands on Hanwha IP Camera ANE-L7012R devices by exploiting improper input sanitizat...

May 23, 2023
CVE-2023-31700
8.8

This vulnerability allows remote attackers to execute arbitrary commands on TP-Link TL-WPA4530 KIT powerline adapters via command injection in the _ht...

May 17, 2023
CVE-2023-31528
8.8

Motorola CX2L Router version 1.0.1 contains a command injection vulnerability in the staticroute_list parameter that allows attackers to execute arbit...

May 11, 2023
CVE-2023-31530
8.8

Motorola CX2L Router version 1.0.1 contains a command injection vulnerability in the smartqos_priority_devices parameter that allows attackers to exec...

May 11, 2023

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,157 CVEs classified as CWE-77, with 445 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free