CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,143
Total CVEs
441
Critical
480
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 78
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 18
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,143)

CVE-2025-50428
9.8

This CVE describes a command injection vulnerability in RaspAP raspap-webgui that allows attackers to execute arbitrary commands on affected systems. ...

Aug 27, 2025
CVE-2025-50722
9.8

This CVE describes an insecure permissions vulnerability in sparkshop v1.1.7 that allows remote attackers to execute arbitrary code via the Common.php...

Aug 25, 2025
CVE-2025-55637
9.8

This CVE describes a command injection vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell firmware that allows attackers to execute arbit...

Aug 22, 2025
CVE-2025-57105
9.8

The DI-7400G+ router contains a command injection vulnerability in its web interface that allows attackers to execute arbitrary system commands. This ...

Aug 22, 2025
CVE-2025-24285
9.8

This CVE describes command injection vulnerabilities in UniFi Connect EV Station Lite that allow attackers with network access to execute arbitrary co...

Aug 21, 2025
CVE-2025-55294
9.8

CVE-2025-55294 is a command injection vulnerability in screenshot-desktop npm package that allows attackers to execute arbitrary shell commands by con...

Aug 19, 2025
CVE-2025-55591
9.8

This critical command injection vulnerability in TOTOLINK-A3002R routers allows attackers to execute arbitrary system commands via the devicemac param...

Aug 18, 2025
CVE-2025-52688
9.8

This vulnerability allows remote attackers to execute arbitrary commands with root privileges on affected Alcatel-Lucent OmniAccess Stellar access poi...

Jul 16, 2025
CVE-2025-49834
9.8

This CVE describes a command injection vulnerability in GPT-SoVITS-WebUI that allows attackers to execute arbitrary commands on the server by manipula...

Jul 15, 2025
CVE-2025-49836
9.8

This CVE describes a command injection vulnerability in GPT-SoVITS-WebUI that allows attackers to execute arbitrary commands on the server by manipula...

Jul 15, 2025
CVE-2025-50756
9.8

This CVE describes a command injection vulnerability in Wavlink WN535K3 routers that allows attackers to execute arbitrary system commands by manipula...

Jul 14, 2025
CVE-2025-45931
9.8

This critical vulnerability in D-Link DIR-816-A2 routers allows remote attackers to execute arbitrary code via the system() function in the goahead bi...

Jun 30, 2025
CVE-2025-5306
EPSS 40% 9.8

CVE-2025-5306 is a command injection vulnerability in Pandora FMS that allows attackers to execute arbitrary operating system commands by manipulating...

Jun 27, 2025
CVE-2025-45986
9.8

This CVE describes a command injection vulnerability in multiple Blink router models that allows attackers to execute arbitrary commands on affected d...

Jun 13, 2025
CVE-2025-45988
9.8

This CVE describes multiple command injection vulnerabilities in Blink routers where attackers can execute arbitrary commands via the cmd parameter in...

Jun 13, 2025
CVE-2025-45984
9.8

This CVE describes a command injection vulnerability in multiple Blink router models via the routepwd parameter. Attackers can execute arbitrary comma...

Jun 13, 2025
CVE-2025-37092
9.8

A command injection vulnerability in HPE StoreOnce Software allows remote attackers to execute arbitrary commands on affected systems. This affects al...

Jun 2, 2025
CVE-2025-37089
9.8

A command injection vulnerability in HPE StoreOnce Software allows remote attackers to execute arbitrary commands on affected systems. This affects al...

Jun 2, 2025
CVE-2025-44084
9.8

This CVE describes a command injection vulnerability in D-link DI-8100 firmware that allows remote attackers to execute arbitrary commands with highes...

May 20, 2025
CVE-2025-45491
9.8

This CVE describes a command injection vulnerability in Linksys E5600 routers via the DynDNS username parameter. Attackers can execute arbitrary comma...

May 6, 2025
CVE-2025-45487
9.8

This CVE describes a command injection vulnerability in the Linksys E5600 router's runtime.InternetConnection function. Attackers can execute arbitrar...

May 6, 2025
CVE-2025-45489
9.8

This CVE describes a command injection vulnerability in Linksys E5600 routers that allows attackers to execute arbitrary commands on the device by man...

May 6, 2025
CVE-2025-43844
9.8

CVE-2025-43844 is a critical command injection vulnerability in Retrieval-based-Voice-Conversion-WebUI that allows attackers to execute arbitrary comm...

May 5, 2025
CVE-2025-43843
9.8

CVE-2025-43843 is a critical command injection vulnerability in Retrieval-based-Voice-Conversion-WebUI that allows attackers to execute arbitrary comm...

May 5, 2025
CVE-2024-57231
9.8

This CVE describes a command injection vulnerability in NETGEAR RAX5 routers that allows attackers to execute arbitrary commands on the device. Attack...

May 5, 2025
CVE-2024-57233
9.8

This vulnerability allows remote attackers to execute arbitrary commands on NETGEAR RAX5 routers by injecting malicious commands through the iface par...

May 5, 2025
CVE-2024-57235
9.8

This vulnerability allows remote attackers to execute arbitrary commands on NETGEAR RAX5 routers by injecting malicious commands through the iface par...

May 5, 2025
CVE-2024-57229
9.8

This vulnerability allows remote attackers to execute arbitrary commands on NETGEAR RAX5 routers by injecting malicious input into the devname paramet...

May 5, 2025
CVE-2025-45042
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC9 routers via the Telnet service. Attackers can gain full control ...

May 5, 2025
CVE-2025-45800
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A950RG routers by exploiting improper input validation in the set...

May 2, 2025
CVE-2025-44872
9.8

This CVE describes a command injection vulnerability in Tenda AC9 routers that allows attackers to execute arbitrary commands via the deviceName param...

May 2, 2025
CVE-2025-29062
9.8

This vulnerability allows remote attackers to execute arbitrary code on BL-AC2100 routers by exploiting improper input validation in the goahead webse...

Apr 2, 2025
CVE-2024-54802
9.8

This vulnerability allows remote attackers to execute arbitrary code on Netgear WNR854T routers via a stack-based buffer overflow in the UPnP service....

Mar 31, 2025
CVE-2025-22939
EPSS 16.4% 9.8

A command injection vulnerability in the telnet service of Adtran 411 ONT devices allows unauthenticated attackers to execute arbitrary commands with ...

Mar 31, 2025
CVE-2025-22941
EPSS 12.9% 9.8

A command injection vulnerability in Adtran 411 ONT web interface allows attackers to execute arbitrary commands with root privileges. This affects sy...

Mar 31, 2025
CVE-2024-55030
EPSS 13% 9.8

A command injection vulnerability in NASA Fprime v3.4.3's Command Dispatcher Service allows attackers to execute arbitrary commands on affected system...

Mar 25, 2025
CVE-2024-8156
9.8

This CVE-2024-8156 is a critical command injection vulnerability in AutoGPT's GitHub Actions workflow. Attackers can inject arbitrary commands by crea...

Mar 20, 2025
CVE-2024-12992
9.8

This critical vulnerability in Pandora FMS allows attackers to execute arbitrary operating system commands through improper input sanitization, leadin...

Mar 17, 2025
CVE-2025-25675
9.8

This CVE describes a command injection vulnerability in Tenda AC10 routers that allows remote attackers to execute arbitrary commands with root privil...

Feb 20, 2025
CVE-2024-55062
9.8

This is a critical code injection vulnerability in EasyVirt DCScope and CO2Scope that allows remote unauthenticated attackers to execute arbitrary cod...

Jan 31, 2025
CVE-2024-57590
9.8

TRENDnet TEW-632BRP routers have a critical OS command injection vulnerability in the ntp_sync.cgi interface that allows remote attackers to execute a...

Jan 27, 2025
CVE-2024-57583
9.8

This CVE describes a command injection vulnerability in Tenda AC18 routers that allows attackers to execute arbitrary commands on the device. Attacker...

Jan 16, 2025
CVE-2025-22912
9.8

CVE-2025-22912 is a command injection vulnerability in RE11S v1.11 that allows attackers to execute arbitrary commands on affected devices via the /go...

Jan 16, 2025
CVE-2024-57223
EPSS 14% 9.8

This CVE describes a command injection vulnerability in Linksys E7350 routers that allows attackers to execute arbitrary commands on the device. The v...

Jan 10, 2025
CVE-2024-57225
EPSS 14% 9.8

This CVE describes a command injection vulnerability in Linksys E7350 routers where an attacker can execute arbitrary commands via the devname paramet...

Jan 10, 2025
CVE-2025-22949
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC9 routers by injecting malicious commands into the SetSambaCfg for...

Jan 10, 2025
CVE-2024-55414
9.8

A vulnerability in Motorola SM56 Modem WDM Driver allows low-privileged users to map physical memory via crafted IOCTL requests. This enables privileg...

Jan 7, 2025
CVE-2022-32203
9.8

This is a critical command injection vulnerability in Huawei terminal printers that allows attackers to execute arbitrary commands with the highest pr...

Dec 20, 2024
CVE-2024-55461
9.8

SeaCMS versions up to 13.0 contain a command injection vulnerability in phome.php through the Ebak_RepPathFiletext() function. This allows attackers t...

Dec 18, 2024
CVE-2024-12356
9.8

This critical vulnerability in BeyondTrust Privileged Remote Access and Remote Support products allows unauthenticated attackers to execute arbitrary ...

Dec 17, 2024

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,143 CVEs classified as CWE-77, with 441 rated critical and 480 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free