CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,188
Total CVEs
460
Critical
507
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 80
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 21
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,188)

CVE-2024-57214
6.3

This CVE describes a command injection vulnerability in TOTOLINK A6000R routers where an attacker can execute arbitrary commands via the devname param...

Jan 10, 2025
CVE-2024-53333
6.3

This CVE describes a command injection vulnerability in TOTOLINK EX200 routers that allows attackers to execute arbitrary system commands via the 'uss...

Nov 21, 2024
CVE-2024-9793
6.3

This critical vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary commands via command injection in the ate_iwpriv_set/...

Oct 10, 2024
CVE-2024-8213
6.3

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious input into the...

Aug 27, 2024
CVE-2024-8211
6.3

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious input into the...

Aug 27, 2024
CVE-2024-8133
6.3

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices via command injection in the HTTP POS...

Aug 24, 2024
CVE-2024-8131
6.3

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by exploiting a command injection fla...

Aug 24, 2024
CVE-2024-8129
6.3

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious commands throu...

Aug 24, 2024
CVE-2024-7907
6.3

This critical vulnerability in TOTOLINK X6000R routers allows remote attackers to execute arbitrary commands via command injection in the setSyslogCfg...

Aug 18, 2024
CVE-2024-7896
6.3

This critical vulnerability in Tosei Online Store Management System allows remote attackers to execute arbitrary commands via command injection in the...

Aug 17, 2024
CVE-2024-7715
6.3

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices through command injection in the phot...

Aug 13, 2024
CVE-2024-7443
6.3

This critical vulnerability in Vivotek IB8367A VVTK-0100b allows remote attackers to execute arbitrary commands via command injection in the upload_fi...

Aug 3, 2024
CVE-2024-7214
6.3

This CVE describes a critical command injection vulnerability in TOTOLINK LR350 routers. Attackers can remotely execute arbitrary commands by manipula...

Jul 30, 2024
CVE-2025-37138
6.2

An authenticated command injection vulnerability in AOS-10 GW and AOS-8 Controllers/Mobility Conductor allows attackers with physical access to execut...

Oct 14, 2025
CVE-2025-57521
6.1

Bambu Studio versions 2.1.1.52 and earlier contain a vulnerability that allows local attackers to execute arbitrary code during application startup. T...

Oct 21, 2025
CVE-2024-8405
6.1

This vulnerability allows attackers to create arbitrary files on Windows PaperCut NG/MF servers with Web Print enabled, potentially flooding disk spac...

Sep 26, 2024
CVE-2025-20278
6.0

This vulnerability allows authenticated local attackers with administrative credentials to execute arbitrary commands as root on affected Cisco Unifie...

Jun 4, 2025
CVE-2025-5525
5.6

CVE-2025-5525 is a critical command injection vulnerability in Jrohy trojan versions up to 2.15.3. Attackers can execute arbitrary operating system co...

Jun 3, 2025
CVE-2024-44610
5.6

This vulnerability allows remote attackers to execute arbitrary commands on PCAN-Ethernet Gateway devices by injecting shell metacharacters in softwar...

Oct 1, 2024
CVE-2026-20675
5.5

This CVE describes an image processing vulnerability in Apple operating systems where improper bounds checks could allow maliciously crafted images to...

Feb 11, 2026
CVE-2025-57733
5.5

This CVE describes an SMTP injection vulnerability in JetBrains TeamCity that allows attackers to modify email content sent by the application. Attack...

Aug 20, 2025
CVE-2025-6897
5.5

This critical vulnerability in D-Link DI-7300G+ routers allows remote attackers to execute arbitrary operating system commands by manipulating the Tim...

Jun 30, 2025
CVE-2024-7616
5.5

A critical command injection vulnerability in Edimax IP cameras allows attackers to execute arbitrary commands on affected devices by manipulating the...

Aug 12, 2024
CVE-2025-70296
5.4

A stored HTML injection vulnerability in Mealie 3.3.1 allows authenticated users to inject arbitrary HTML into recipe notes, which can lead to user in...

Feb 11, 2026
CVE-2026-21639
5.4

This vulnerability allows attackers within Wi-Fi range to execute arbitrary code on affected Ubiquiti airMAX and airFiber devices by exploiting a flaw...

Jan 8, 2026
CVE-2025-60671
5.4

A command injection vulnerability in D-Link DIR-823G router firmware allows attackers with write access to /var/system/linux_vlan_reinit to execute ar...

Nov 13, 2025
CVE-2025-60689
5.4

An unauthenticated command injection vulnerability in Linksys E1200 v2 routers allows remote attackers to execute arbitrary commands on the device wit...

Nov 13, 2025
CVE-2025-50817
5.4

CVE-2025-50817 is a disputed vulnerability in Python-Future 1.0.0 where the module automatically imports a file named test.py if present in accessible...

Aug 14, 2025
CVE-2025-54393
5.4

CVE-2025-54393 is a static code injection vulnerability in Netwrix Directory Manager (formerly Imanami GroupID) that allows authenticated users to exe...

Aug 7, 2025
CVE-2025-52377
5.4

This command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router allows authenticated attackers to execute arbitrary commands as root via...

Jul 15, 2025
CVE-2025-20258
5.4

An unauthenticated remote attacker can inject arbitrary commands into emails sent by Cisco Duo's self-service portal due to insufficient input validat...

May 21, 2025
CVE-2025-25768
5.4

MRCMS v3.1.2 contains a server-side template injection vulnerability in DispatcherServlet.java that allows attackers to execute arbitrary code on the ...

Feb 21, 2025
CVE-2025-46365
5.3

Dell CloudLink versions before 8.1.1 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary commands on af...

Nov 5, 2025
CVE-2025-29519
5.3

A command injection vulnerability in D-Link DSL-7740C routers allows attackers to execute arbitrary commands via crafted GET requests targeting the EX...

Aug 25, 2025
CVE-2025-9176
5.3

This CVE describes a command injection vulnerability in neurobin shc versions up to 4.0.3. Attackers with local access can execute arbitrary operating...

Aug 20, 2025
CVE-2025-9174
5.3

This vulnerability in neurobin shc up to version 4.0.3 allows local command injection through the filename handler component. Attackers with local acc...

Aug 19, 2025
CVE-2025-45011
5.3

A HTML injection vulnerability in PHPGurukul Park Ticketing Management System v2.0 allows remote attackers to inject malicious HTML/JavaScript via the...

Apr 30, 2025
CVE-2025-45009
5.3

A HTML injection vulnerability in PHPGurukul Park Ticketing Management System v2.0 allows remote attackers to inject malicious HTML/JavaScript via the...

Apr 30, 2025
CVE-2023-33300
5.3

This command injection vulnerability in Fortinet FortiNAC allows attackers to execute arbitrary commands on affected systems via specially crafted req...

Mar 14, 2025
CVE-2024-57685
5.3

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of sparkshop by uploading a specially craf...

Feb 24, 2025
CVE-2024-38894
5.3

This CVE describes a command injection vulnerability in WAVLINK WN551K1 routers where attackers can execute arbitrary commands via the IP parameter in...

Jun 24, 2024
CVE-2024-38896
5.3

This CVE describes a command injection vulnerability in WAVLINK WN551K1 routers through the start_hour parameter of the nightled.cgi script. Attackers...

Jun 24, 2024
CVE-2025-65885
5.1

This vulnerability allows local attackers to inject startup scripts via crafted .txt files in the Data directory on Nokia Symbian Belle devices runnin...

Dec 26, 2025
CVE-2025-64052
5.1

This vulnerability allows unauthenticated attackers on the same local network to execute arbitrary system commands on Fanvil x210 V2 IP phones. Attack...

Dec 5, 2025
CVE-2025-60855
5.1

CVE-2025-60855 is a firmware validation vulnerability in Reolink Video Doorbell WiFi DB_566128M5MP_W that allows attackers to bypass signature checks ...

Oct 16, 2025
CVE-2025-4089
5.1

This vulnerability in Firefox and Thunderbird's 'copy as cURL' feature allows attackers to craft malicious commands with insufficient escaping of spec...

Apr 29, 2025
CVE-2025-25802
5.1

SeaCMS v13.3 contains a remote code execution vulnerability in the admin_ip.php component that allows attackers to execute arbitrary code on affected ...

Feb 26, 2025
CVE-2025-25793
5.1

SeaCMS v13.3 contains a remote code execution vulnerability in the admin_notify.php component that allows attackers to execute arbitrary code on affec...

Feb 26, 2025
CVE-2025-25796
5.1

SeaCMS v13.3 contains a remote code execution vulnerability in admin_template.php that allows attackers to execute arbitrary code on affected systems....

Feb 26, 2025
CVE-2024-57212
5.1

This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows attackers to execute arbitrary commands via the opmode par...

Jan 10, 2025

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,188 CVEs classified as CWE-77, with 460 rated critical and 507 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free