CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,188)
This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers. Attackers can exploit the 'exportOvpn' function via the web inter...
Dec 13, 2025This vulnerability allows remote attackers to execute arbitrary operating system commands on systems running TykoDev cherry-studio-TykoFork 0.1. Attac...
Dec 7, 2025This CVE describes an OS command injection vulnerability in DesktopCommanderMCP versions up to 0.2.13. Attackers can remotely execute arbitrary operat...
Oct 8, 2025This CVE describes an OS command injection vulnerability in DesktopCommanderMCP up to version 0.2.13. Attackers can execute arbitrary commands on the ...
Oct 8, 2025This CVE describes an OS command injection vulnerability in D-Link DI-7001 MINI routers through the /upgrade_filter.asp file's path parameter. Attacke...
Oct 7, 2025This CVE describes a remote command injection vulnerability in wenkucms versions up to 3.4. Attackers can execute arbitrary operating system commands ...
Sep 29, 2025This vulnerability allows remote attackers to execute arbitrary operating system commands via command injection in the OAuth Server Discovery componen...
Sep 17, 2025This CVE describes an OS command injection vulnerability in D-Link routers' web interface. Attackers can execute arbitrary commands remotely by manipu...
Sep 15, 2025This vulnerability allows remote attackers to execute arbitrary operating system commands on Tenda AC9 and AC15 routers through command injection in t...
Sep 15, 2025This CVE describes an OS command injection vulnerability in D-Link routers' jhttpd component via the usb_paswd.asp file. Attackers can execute arbitra...
Sep 15, 2025This CVE describes a remote command injection vulnerability in MiczFlor RPi-Jukebox-RFID versions up to 2.8.0. Attackers can execute arbitrary operati...
Sep 12, 2025This CVE describes an OS command injection vulnerability in LB-LINK BL-X26 routers version 1.2.8. Attackers can remotely execute arbitrary commands on...
Aug 28, 2025This CVE describes a remote command injection vulnerability in multiple Linksys RE-series Wi-Fi range extender models. Attackers can execute arbitrary...
Aug 28, 2025This CVE describes an OS command injection vulnerability in DCN DCME-720 web management backend. Attackers can execute arbitrary commands on affected ...
Aug 24, 2025This CVE describes an OS command injection vulnerability in Linksys RE series range extenders. Attackers can remotely execute arbitrary commands by ma...
Aug 20, 2025This CVE describes a remote command injection vulnerability in multiple Linksys RE-series range extenders. Attackers can execute arbitrary operating s...
Aug 11, 2025This CVE describes a remote command injection vulnerability in Linksys RE series range extenders. Attackers can execute arbitrary operating system com...
Aug 11, 2025This CVE describes an OS command injection vulnerability in Linksys WiFi range extenders that allows remote attackers to execute arbitrary commands on...
Aug 11, 2025This CVE describes a command injection vulnerability in Linksys range extender firmware that allows remote attackers to execute arbitrary operating sy...
Aug 11, 2025This critical vulnerability in SkyworkAI DeepResearchAgent allows remote attackers to execute arbitrary operating system commands through command inje...
Aug 6, 2025This critical vulnerability allows remote attackers to execute arbitrary operating system commands through command injection in the Model Context Prot...
Aug 6, 2025This critical vulnerability in Netgear D6400 routers allows remote attackers to execute arbitrary operating system commands via command injection in t...
Jul 10, 2025This critical vulnerability in TOTOLINK N200RE routers allows remote attackers to execute arbitrary operating system commands by manipulating the Host...
Jul 8, 2025This critical vulnerability in Belkin F9K1122 routers allows remote attackers to execute arbitrary operating system commands via command injection in ...
Jul 6, 2025CVE-2025-7081 is a critical OS command injection vulnerability in Belkin F9K1122 routers that allows remote attackers to execute arbitrary commands by...
Jul 6, 2025This critical vulnerability in TOTOLINK CA300-PoE routers allows remote attackers to execute arbitrary operating system commands by manipulating time ...
Jun 25, 2025This critical vulnerability in TOTOLINK CA300-PoE routers allows remote attackers to execute arbitrary operating system commands by manipulating the F...
Jun 25, 2025This critical vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK A3002R routers by manipulating the wlan...
Jun 22, 2025This critical vulnerability in Linksys RE series range extenders allows remote attackers to execute arbitrary operating system commands via command in...
Jun 2, 2025This critical vulnerability in Linksys wireless range extenders allows remote attackers to execute arbitrary operating system commands via command inj...
Jun 2, 2025This critical vulnerability in Linksys WiFi range extenders allows remote attackers to execute arbitrary operating system commands by manipulating the...
Jun 2, 2025A critical OS command injection vulnerability in Linksys RE series WiFi extenders allows remote attackers to execute arbitrary commands on affected de...
Jun 2, 2025This CVE describes a command injection vulnerability in Tenda W20E routers that allows attackers to execute arbitrary commands on the device. Attacker...
May 1, 2025This CVE describes a command injection vulnerability in TOTOLINK CA300-POE routers that allows attackers to execute arbitrary system commands via a cr...
May 1, 2025This CVE describes a command injection vulnerability in Tenda W20E routers that allows attackers to execute arbitrary commands on the device. Attacker...
May 1, 2025This CVE describes a command injection vulnerability in TOTOLINK CA600-PoE routers that allows attackers to execute arbitrary commands via the fwUrl p...
May 1, 2025This command injection vulnerability in TOTOLINK CP900 routers allows attackers to execute arbitrary system commands by manipulating the hour or minut...
May 1, 2025This CVE describes a command injection vulnerability in TOTOLINK CP900 routers that allows attackers to execute arbitrary system commands through the ...
May 1, 2025This CVE describes a command injection vulnerability in TOTOLINK CP900 routers that allows attackers to execute arbitrary system commands via the File...
May 1, 2025CVE-2024-46089 is a remote code execution vulnerability in 74cms background interface apiadmin that allows attackers to execute arbitrary code on affe...
Apr 18, 2025This critical vulnerability in OpenManus allows remote attackers to execute arbitrary operating system commands through the Python execution component...
Mar 25, 2025This critical vulnerability in AMTT Hotel Broadband Operation System 1.0 allows remote attackers to execute arbitrary operating system commands via co...
Mar 24, 2025This CVE describes a command injection vulnerability in Linksys E5600 routers where an attacker can execute arbitrary commands via the pt["count"] par...
Mar 21, 2025This CVE describes a critical OS command injection vulnerability in Oiwtech OIW-2431APGN-HP wireless access points. Attackers can remotely execute arb...
Mar 17, 2025This critical vulnerability in TOTOLINK EX1800T routers allows remote attackers to execute arbitrary operating system commands through command injecti...
Mar 7, 2025This critical vulnerability in TOTOLINK EX1800T routers allows remote attackers to execute arbitrary operating system commands via command injection i...
Mar 7, 2025This critical vulnerability in hzmanyun Education and Training System allows remote attackers to execute arbitrary operating system commands via comma...
Feb 25, 2025This CVE describes a critical OS command injection vulnerability in LB-LINK AC1900 routers. Attackers can remotely execute arbitrary commands on affec...
Feb 24, 2025This critical vulnerability in TOTOLINK X18 routers allows remote attackers to execute arbitrary operating system commands by manipulating the 'enable...
Feb 16, 2025This CVE describes a command injection vulnerability in Linksys E7350 routers where an attacker can execute arbitrary commands via the ifname paramete...
Jan 10, 2025About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,188 CVEs classified as CWE-77, with 460 rated critical and 507 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free