CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,188
Total CVEs
460
Critical
507
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 80
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 21
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,188)

CVE-2025-14586
6.3

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers. Attackers can exploit the 'exportOvpn' function via the web inter...

Dec 13, 2025
CVE-2025-14204
6.3

This vulnerability allows remote attackers to execute arbitrary operating system commands on systems running TykoDev cherry-studio-TykoFork 0.1. Attac...

Dec 7, 2025
CVE-2025-11491
6.3

This CVE describes an OS command injection vulnerability in DesktopCommanderMCP versions up to 0.2.13. Attackers can remotely execute arbitrary operat...

Oct 8, 2025
CVE-2025-11490
6.3

This CVE describes an OS command injection vulnerability in DesktopCommanderMCP up to version 0.2.13. Attackers can execute arbitrary commands on the ...

Oct 8, 2025
CVE-2025-11407
6.3

This CVE describes an OS command injection vulnerability in D-Link DI-7001 MINI routers through the /upgrade_filter.asp file's path parameter. Attacke...

Oct 7, 2025
CVE-2025-11138
6.3

This CVE describes a remote command injection vulnerability in wenkucms versions up to 3.4. Attackers can execute arbitrary operating system commands ...

Sep 29, 2025
CVE-2025-10619
6.3

This vulnerability allows remote attackers to execute arbitrary operating system commands via command injection in the OAuth Server Discovery componen...

Sep 17, 2025
CVE-2025-10441
6.3

This CVE describes an OS command injection vulnerability in D-Link routers' web interface. Attackers can execute arbitrary commands remotely by manipu...

Sep 15, 2025
CVE-2025-10442
6.3

This vulnerability allows remote attackers to execute arbitrary operating system commands on Tenda AC9 and AC15 routers through command injection in t...

Sep 15, 2025
CVE-2025-10440
6.3

This CVE describes an OS command injection vulnerability in D-Link routers' jhttpd component via the usb_paswd.asp file. Attackers can execute arbitra...

Sep 15, 2025
CVE-2025-10327
6.3

This CVE describes a remote command injection vulnerability in MiczFlor RPi-Jukebox-RFID versions up to 2.8.0. Attackers can execute arbitrary operati...

Sep 12, 2025
CVE-2025-9579
6.3

This CVE describes an OS command injection vulnerability in LB-LINK BL-X26 routers version 1.2.8. Attackers can remotely execute arbitrary commands on...

Aug 28, 2025
CVE-2025-9575
6.3

This CVE describes a remote command injection vulnerability in multiple Linksys RE-series Wi-Fi range extender models. Attackers can execute arbitrary...

Aug 28, 2025
CVE-2025-9387
6.3

This CVE describes an OS command injection vulnerability in DCN DCME-720 web management backend. Attackers can execute arbitrary commands on affected ...

Aug 24, 2025
CVE-2025-9244
6.3

This CVE describes an OS command injection vulnerability in Linksys RE series range extenders. Attackers can remotely execute arbitrary commands by ma...

Aug 20, 2025
CVE-2025-8830
6.3

This CVE describes a remote command injection vulnerability in multiple Linksys RE-series range extenders. Attackers can execute arbitrary operating s...

Aug 11, 2025
CVE-2025-8829
6.3

This CVE describes a remote command injection vulnerability in Linksys RE series range extenders. Attackers can execute arbitrary operating system com...

Aug 11, 2025
CVE-2025-8828
6.3

This CVE describes an OS command injection vulnerability in Linksys WiFi range extenders that allows remote attackers to execute arbitrary commands on...

Aug 11, 2025
CVE-2025-8821
6.3

This CVE describes a command injection vulnerability in Linksys range extender firmware that allows remote attackers to execute arbitrary operating sy...

Aug 11, 2025
CVE-2025-8667
6.3

This critical vulnerability in SkyworkAI DeepResearchAgent allows remote attackers to execute arbitrary operating system commands through command inje...

Aug 6, 2025
CVE-2025-8665
6.3

This critical vulnerability allows remote attackers to execute arbitrary operating system commands through command injection in the Model Context Prot...

Aug 6, 2025
CVE-2025-7407
6.3

This critical vulnerability in Netgear D6400 routers allows remote attackers to execute arbitrary operating system commands via command injection in t...

Jul 10, 2025
CVE-2025-7154
6.3

This critical vulnerability in TOTOLINK N200RE routers allows remote attackers to execute arbitrary operating system commands by manipulating the Host...

Jul 8, 2025
CVE-2025-7083
6.3

This critical vulnerability in Belkin F9K1122 routers allows remote attackers to execute arbitrary operating system commands via command injection in ...

Jul 6, 2025
CVE-2025-7081
6.3

CVE-2025-7081 is a critical OS command injection vulnerability in Belkin F9K1122 routers that allows remote attackers to execute arbitrary commands by...

Jul 6, 2025
CVE-2025-6621
6.3

This critical vulnerability in TOTOLINK CA300-PoE routers allows remote attackers to execute arbitrary operating system commands by manipulating time ...

Jun 25, 2025
CVE-2025-6619
6.3

This critical vulnerability in TOTOLINK CA300-PoE routers allows remote attackers to execute arbitrary operating system commands by manipulating the F...

Jun 25, 2025
CVE-2025-6485
6.3

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK A3002R routers by manipulating the wlan...

Jun 22, 2025
CVE-2025-5445
6.3

This critical vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary operating system commands via command in...

Jun 2, 2025
CVE-2025-5443
6.3

This critical vulnerability in Linksys wireless range extenders allows remote attackers to execute arbitrary operating system commands via command inj...

Jun 2, 2025
CVE-2025-5441
6.3

This critical vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary operating system commands by manipulating the...

Jun 2, 2025
CVE-2025-5439
6.3

A critical OS command injection vulnerability in Linksys RE series WiFi extenders allows remote attackers to execute arbitrary commands on affected de...

Jun 2, 2025
CVE-2025-44866
6.3

This CVE describes a command injection vulnerability in Tenda W20E routers that allows attackers to execute arbitrary commands on the device. Attacker...

May 1, 2025
CVE-2025-44862
6.3

This CVE describes a command injection vulnerability in TOTOLINK CA300-POE routers that allows attackers to execute arbitrary system commands via a cr...

May 1, 2025
CVE-2025-44864
6.3

This CVE describes a command injection vulnerability in Tenda W20E routers that allows attackers to execute arbitrary commands on the device. Attacker...

May 1, 2025
CVE-2025-44846
6.3

This CVE describes a command injection vulnerability in TOTOLINK CA600-PoE routers that allows attackers to execute arbitrary commands via the fwUrl p...

May 1, 2025
CVE-2025-44836
6.3

This command injection vulnerability in TOTOLINK CP900 routers allows attackers to execute arbitrary system commands by manipulating the hour or minut...

May 1, 2025
CVE-2025-44838
6.3

This CVE describes a command injection vulnerability in TOTOLINK CP900 routers that allows attackers to execute arbitrary system commands through the ...

May 1, 2025
CVE-2025-44854
6.3

This CVE describes a command injection vulnerability in TOTOLINK CP900 routers that allows attackers to execute arbitrary system commands via the File...

May 1, 2025
CVE-2024-46089
6.3

CVE-2024-46089 is a remote code execution vulnerability in 74cms background interface apiadmin that allows attackers to execute arbitrary code on affe...

Apr 18, 2025
CVE-2025-2733
6.3

This critical vulnerability in OpenManus allows remote attackers to execute arbitrary operating system commands through the Python execution component...

Mar 25, 2025
CVE-2025-2701
6.3

This critical vulnerability in AMTT Hotel Broadband Operation System 1.0 allows remote attackers to execute arbitrary operating system commands via co...

Mar 24, 2025
CVE-2025-29226
6.3

This CVE describes a command injection vulnerability in Linksys E5600 routers where an attacker can execute arbitrary commands via the pt["count"] par...

Mar 21, 2025
CVE-2025-2367
6.3

This CVE describes a critical OS command injection vulnerability in Oiwtech OIW-2431APGN-HP wireless access points. Attackers can remotely execute arb...

Mar 17, 2025
CVE-2025-2096
6.3

This critical vulnerability in TOTOLINK EX1800T routers allows remote attackers to execute arbitrary operating system commands through command injecti...

Mar 7, 2025
CVE-2025-2094
6.3

This critical vulnerability in TOTOLINK EX1800T routers allows remote attackers to execute arbitrary operating system commands via command injection i...

Mar 7, 2025
CVE-2025-1676
6.3

This critical vulnerability in hzmanyun Education and Training System allows remote attackers to execute arbitrary operating system commands via comma...

Feb 25, 2025
CVE-2025-1609
6.3

This CVE describes a critical OS command injection vulnerability in LB-LINK AC1900 routers. Attackers can remotely execute arbitrary commands on affec...

Feb 24, 2025
CVE-2025-1339
6.3

This critical vulnerability in TOTOLINK X18 routers allows remote attackers to execute arbitrary operating system commands by manipulating the 'enable...

Feb 16, 2025
CVE-2024-57222
6.3

This CVE describes a command injection vulnerability in Linksys E7350 routers where an attacker can execute arbitrary commands via the ifname paramete...

Jan 10, 2025

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,188 CVEs classified as CWE-77, with 460 rated critical and 507 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free