CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,188
Total CVEs
460
Critical
507
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 80
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 21
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,188)

CVE-2025-56426
6.5

A remote code execution vulnerability in WebKul Bagisto v2.3.6 allows attackers to execute arbitrary code via the Cart/Checkout API endpoint. The pric...

Oct 9, 2025
CVE-2025-56769
6.5

A vulnerability in chinabugotech hutool's QLExpressEngine class allows attackers to execute arbitrary expressions, leading to arbitrary method invocat...

Sep 25, 2025
CVE-2025-29157
6.5

This vulnerability in petstore v1.0.7 allows remote attackers to execute arbitrary code by accessing a non-existent endpoint that triggers a 404 error...

Sep 25, 2025
CVE-2025-29155
6.5

A command injection vulnerability in petstore v1.0.7 allows remote attackers to execute arbitrary code via the DELETE endpoint. This affects any syste...

Sep 25, 2025
CVE-2025-45326
6.5

This vulnerability allows remote attackers to execute arbitrary code on PocketVJ CP systems via the submit_size.php component. It affects PocketVJ-CP-...

Sep 23, 2025
CVE-2025-57296
6.5

This CVE describes a command injection vulnerability in Tenda AC6 router firmware that allows attackers to execute arbitrary system commands. The vuln...

Sep 19, 2025
CVE-2025-55911
6.5

This vulnerability in ClipBucket v5.5.2 Build#90 allows remote attackers to execute arbitrary code via the file_downloader.php component by manipulati...

Sep 18, 2025
CVE-2025-55824
6.5

ModStartCMS v9.5.0 contains an arbitrary file write vulnerability that allows attackers to upload malicious files to the server. This can lead to remo...

Sep 2, 2025
CVE-2025-50755
6.5

This vulnerability allows attackers to execute arbitrary commands on Wavlink WN535K3 routers by sending specially crafted requests to the set_sys_cmd ...

Sep 2, 2025
CVE-2025-50757
6.5

This CVE describes a command injection vulnerability in Wavlink WN535K3 routers that allows attackers to execute arbitrary system commands by manipula...

Sep 2, 2025
CVE-2025-44179
6.5

This CVE describes a command injection vulnerability in Hitron CGNF-TWN routers that allows attackers to execute arbitrary commands through the telnet...

Aug 25, 2025
CVE-2025-29522
6.5

This CVE describes a command injection vulnerability in D-Link DSL-7740C routers that allows authenticated attackers to execute arbitrary commands via...

Aug 25, 2025
CVE-2025-50461
6.5

This CVE describes a deserialization vulnerability in Volcengine's verl 3.0.0 that allows arbitrary code execution when loading malicious model files....

Aug 19, 2025
CVE-2025-55590
6.5

This CVE describes a command injection vulnerability in TOTOLINK A3002R routers via the bupload.html component. Attackers can execute arbitrary comman...

Aug 18, 2025
CVE-2025-50515
6.5

This vulnerability allows attackers to execute arbitrary code on systems running phome Empirebak 2010 when the vulnerable config.php file is loaded. T...

Aug 14, 2025
CVE-2025-53774
6.5

This vulnerability in Microsoft 365 Copilot BizChat allows authenticated attackers to access sensitive information from other users' business chats. I...

Aug 7, 2025
CVE-2025-47188
6.5

This CVE describes a command injection vulnerability in Mitel SIP phones that allows unauthenticated attackers to execute arbitrary commands on affect...

Aug 7, 2025
CVE-2025-45512
6.5

This vulnerability in U-Boot v1.1.3 allows attackers to bypass signature verification during firmware updates, enabling installation of malicious firm...

Aug 5, 2025
CVE-2025-50688
6.5

This CVE describes a command injection vulnerability in TwistedWeb 14.0.0 that allows remote attackers to execute arbitrary commands on affected syste...

Aug 5, 2025
CVE-2025-25692
6.5

A PHAR deserialization vulnerability in PrestaShop v8.2.0 allows attackers to execute arbitrary code on the server by sending a specially crafted POST...

Jul 30, 2025
CVE-2025-52284
EPSS 27.3% 6.5

This CVE describes an unauthenticated command injection vulnerability in Totolink X6000R routers. Attackers can execute arbitrary system commands by s...

Jul 29, 2025
CVE-2025-27953
6.5

A session management vulnerability in Clinical Collaboration Platform 12.2.1.5 allows remote attackers to obtain sensitive information and execute arb...

Jun 2, 2025
CVE-2024-57338
6.5

This vulnerability allows attackers to upload malicious files to M2Soft CROWNIX Report & ERS systems, potentially leading to remote code execution. Af...

May 28, 2025
CVE-2025-46176
6.5

This vulnerability involves hardcoded credentials in the Telnet service of specific D-Link router models, allowing attackers to remotely execute arbit...

May 23, 2025
CVE-2024-55466
6.5

This CVE describes an arbitrary file upload vulnerability in ThingsBoard's Image Gallery component that allows attackers to upload malicious files and...

May 12, 2025
CVE-2025-44176
6.5

This vulnerability allows remote attackers to execute arbitrary code on Tenda FH451 routers running firmware version V1.0.0.9. The flaw exists in the ...

May 12, 2025
CVE-2025-44023
6.5

This vulnerability allows remote attackers to execute arbitrary commands on affected D-Link network-attached storage (NAS) devices by exploiting impro...

May 8, 2025
CVE-2025-26262
6.5

This vulnerability in Linux Malware Detect (LMD) allows attackers to escalate privileges and execute arbitrary code by supplying a file with a special...

May 6, 2025
CVE-2025-25504
6.5

This vulnerability allows unauthenticated attackers with network access to connect to TCP port 4444 on affected Gefen WebFWC devices and execute arbit...

May 5, 2025
CVE-2025-44860
6.5

This CVE describes a command injection vulnerability in TOTOLINK CA300-POE routers that allows attackers to execute arbitrary system commands via the ...

May 1, 2025
CVE-2025-44848
6.5

This CVE describes a command injection vulnerability in TOTOLINK CA600-PoE routers that allows attackers to execute arbitrary commands via crafted req...

May 1, 2025
CVE-2025-44840
6.5

This CVE describes a command injection vulnerability in TOTOLINK CA600-PoE routers that allows attackers to execute arbitrary commands via the svn par...

May 1, 2025
CVE-2025-44842
6.5

This CVE describes a command injection vulnerability in TOTOLINK CA600-PoE routers that allows attackers to execute arbitrary system commands via the ...

May 1, 2025
CVE-2025-44844
6.5

This CVE describes a command injection vulnerability in TOTOLINK CA600-PoE routers that allows attackers to execute arbitrary commands via the FileNam...

May 1, 2025
CVE-2025-28143
6.5

This CVE describes a command injection vulnerability in Edimax AC1200 routers that allows authenticated attackers to execute arbitrary commands on the...

Apr 15, 2025
CVE-2025-28145
6.5

This CVE describes a command injection vulnerability in Edimax AC1200 routers that allows attackers to execute arbitrary commands on the device. The v...

Apr 15, 2025
CVE-2025-25605
6.5

This vulnerability allows remote attackers to execute arbitrary commands on Totolink X5000R routers through command injection in the apcli_wps_gen_pin...

Feb 21, 2025
CVE-2024-53615
EPSS 18% 6.5

This CVE describes a command injection vulnerability in Karl Ward's files.gallery video thumbnail rendering component. Attackers can execute arbitrary...

Jan 30, 2025
CVE-2024-39438
6.5

This vulnerability in linkturbonative service allows command injection through improper input validation. An attacker with System execution privileges...

Oct 9, 2024
CVE-2024-39436
6.5

This vulnerability in linkturbonative service allows command injection through improper input validation, enabling local privilege escalation. Attacke...

Oct 9, 2024
CVE-2024-20365
6.5

This vulnerability allows authenticated administrators to execute arbitrary commands through the Redfish API on affected Cisco UCS servers, potentiall...

Oct 2, 2024
CVE-2025-66404
6.4

This CVE describes a command injection vulnerability in the exec_in_pod tool of mcp-server-kubernetes. When commands are provided in string format, th...

Dec 3, 2025
CVE-2025-54131
6.4

This vulnerability allows attackers to bypass Cursor code editor's allowlist in auto-run mode using backtick (`) or $(cmd) syntax, enabling arbitrary ...

Aug 1, 2025
CVE-2024-51772
6.4

An authenticated remote code execution vulnerability in ClearPass Policy Manager's web interface allows authenticated attackers to execute arbitrary c...

Dec 3, 2024
CVE-2024-7110
6.4

This CVE allows attackers to execute arbitrary commands in GitLab CI/CD pipelines through prompt injection. Attackers can manipulate pipeline configur...

Aug 22, 2024
CVE-2026-3101
6.3

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Intelbras TIP 635G routers through the Ping Handle...

Feb 24, 2026
CVE-2026-2167
6.3

This CVE describes a remote command injection vulnerability in Totolink WA300 routers. Attackers can execute arbitrary operating system commands by ma...

Feb 8, 2026
CVE-2026-2131
6.3

This vulnerability allows remote attackers to execute arbitrary operating system commands on systems running XixianLiang HarmonyOS-mcp-server 0.1.0. A...

Feb 8, 2026
CVE-2026-1544
6.3

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers via the lan_gateway parameter in the /goform/set_mode endpoint. At...

Jan 28, 2026
CVE-2025-15254
6.3

This vulnerability allows remote attackers to execute arbitrary operating system commands on Tenda W6-S routers via command injection in the ATE Servi...

Dec 30, 2025

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,188 CVEs classified as CWE-77, with 460 rated critical and 507 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free