CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,149
Total CVEs
443
Critical
484
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 18
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,149)

CVE-2024-24377
9.8

This vulnerability in idocv v.14.1.3_20231228 allows remote attackers to execute arbitrary code and access sensitive information through crafted scrip...

Feb 16, 2024
CVE-2023-46687
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on Emerson gas chromatograph devices. Af...

Feb 9, 2024
CVE-2024-24321
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816A2 routers via a command injection flaw in the wizardstep4_ssid_...

Feb 8, 2024
CVE-2024-23745
9.8

CVE-2024-23745 is a Dirty NIB attack vulnerability in Notion Web Clipper 1.0.3(7) where manipulated .nib files can execute arbitrary commands. Even wi...

Jan 31, 2024
CVE-2023-52038
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers through the sub_415C80 function. Attackers can gai...

Jan 24, 2024
CVE-2023-52040
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via the sub_41284C function. Attackers can gain fu...

Jan 24, 2024
CVE-2023-51887
9.8

CVE-2023-51887 is a critical command injection vulnerability in Mathtex v1.05 and earlier that allows remote attackers to execute arbitrary commands o...

Jan 24, 2024
CVE-2024-22651
9.8

A command injection vulnerability in the ssdpcgi_main function of the cgibin binary in D-Link DIR-815 router firmware allows remote attackers to execu...

Jan 24, 2024
CVE-2023-52027
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink A3700R routers via the NTPSyncWithHost function. Attackers can ga...

Jan 11, 2024
CVE-2023-51126
9.8

This CVE describes a command injection vulnerability in FLIR AX8 thermal cameras that allows attackers to execute arbitrary commands on the device via...

Jan 10, 2024
CVE-2023-31446
9.8

This vulnerability allows remote attackers to execute arbitrary Bash commands with root privileges on Cassia Gateway devices by exploiting unsanitized...

Jan 10, 2024
CVE-2023-51707
9.8

CVE-2023-51707 is a critical command injection vulnerability in Array Networks' MotionPro VPN client on AG and vxAG appliances. It allows remote attac...

Dec 22, 2023
CVE-2023-50989
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda i29 routers through the pingSet function. Attackers can gain full co...

Dec 20, 2023
CVE-2023-50983
9.8

This CVE describes a command injection vulnerability in Tenda i29 routers that allows attackers to execute arbitrary commands on the device. The vulne...

Dec 20, 2023
CVE-2023-50089
9.8

This vulnerability allows authenticated attackers to execute arbitrary commands on NETGEAR WNR2000v4 routers via HTTP SOAP authentication. Attackers w...

Dec 15, 2023
CVE-2013-2513
9.8

The flash_tool gem for Ruby versions through 0.6.0 contains a command injection vulnerability that allows attackers to execute arbitrary commands on t...

Dec 12, 2023
CVE-2023-49431
9.8

This CVE describes a command injection vulnerability in Tenda AX9 routers that allows attackers to execute arbitrary commands on the device. The vulne...

Dec 7, 2023
CVE-2023-49435
9.8

Tenda AX9 routers running firmware version V22.03.01.46 contain a command injection vulnerability in the SetNetControlList function. This allows attac...

Dec 7, 2023
CVE-2023-49428
9.8

This CVE describes a command injection vulnerability in Tenda AX12 routers where an attacker can execute arbitrary commands via the 'mac' parameter in...

Dec 7, 2023
CVE-2023-48801
9.8

This vulnerability allows remote command execution on TOTOLINK X6000R routers by exploiting improper input validation in the shttpd component. Attacke...

Dec 1, 2023
CVE-2023-48842
9.8

This CVE describes a command injection vulnerability in D-Link Go-RT-AC750 routers that allows attackers to execute arbitrary commands via the service...

Dec 1, 2023
CVE-2023-43453
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X6000R routers by exploiting improper input validation in the setDiag...

Dec 1, 2023
CVE-2023-43455
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK X6000R routers via the command parameter in the setting/setTraceroute...

Dec 1, 2023
CVE-2023-49040
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX1803 routers by sending specially crafted requests to the adslPwd para...

Nov 27, 2023
CVE-2023-49210
9.8

CVE-2023-49210 is a critical command injection vulnerability in the malicious 'openssl' NPM package (also called node-openssl) that allows attackers t...

Nov 23, 2023
CVE-2023-47253
9.8

This vulnerability allows remote attackers to execute arbitrary PHP code on Qualitor systems through improper input validation in the gridValoresPopHi...

Nov 6, 2023
CVE-2023-46484
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOlink X6000R routers via the setLedCfg function. Attackers can gain full co...

Oct 31, 2023
CVE-2023-46993
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3300R routers by exploiting improper input validation in the set...

Oct 31, 2023
CVE-2023-46976
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3300R routers by injecting malicious commands into the file_name...

Oct 31, 2023
CVE-2023-46979
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via command injection in the setLedCfg function. A...

Oct 31, 2023
CVE-2023-45498
9.8

CVE-2023-45498 is a command injection vulnerability in VinChin Backup & Recovery software that allows attackers to execute arbitrary commands on affec...

Oct 27, 2023
CVE-2023-46409
9.8

This CVE describes a command execution vulnerability in TOTOLINK X6000R routers that allows attackers to execute arbitrary commands on the device. The...

Oct 25, 2023
CVE-2023-46411
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via the sub_415258 function. It affects users runn...

Oct 25, 2023
CVE-2023-46413
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via the sub_4155DC function. Attackers can gain fu...

Oct 25, 2023
CVE-2023-46415
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via the sub_41E588 function. Attackers can gain fu...

Oct 25, 2023
CVE-2023-46417
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers without authentication via a specific function. It...

Oct 25, 2023
CVE-2023-46419
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via a specific function. Attackers can gain full c...

Oct 25, 2023
CVE-2023-46421
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via a specific function (sub_411D00). Attackers ca...

Oct 25, 2023
CVE-2023-46423
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers via the sub_417094 function. Attackers can gain fu...

Oct 25, 2023
CVE-2023-46574
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3700R routers by exploiting the FileName parameter in the UploadFirm...

Oct 25, 2023
CVE-2023-36953
9.8

CVE-2023-36953 is a command injection vulnerability in TOTOLINK CP300+ routers that allows attackers to execute arbitrary commands on affected devices...

Oct 16, 2023
CVE-2023-45852
9.8

This vulnerability allows unauthenticated attackers to bypass authentication and execute arbitrary commands on Vitogate 300 devices by injecting shell...

Oct 14, 2023
CVE-2023-45465
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Netis N3Mv2 routers by injecting malicious code into the ddnsDomainName pa...

Oct 13, 2023
CVE-2023-43891
9.8

CVE-2023-43891 is a command injection vulnerability in Netis N3Mv2 routers that allows attackers to execute arbitrary commands on the device by sendin...

Oct 2, 2023
CVE-2023-43202
9.8

This CVE describes a critical command injection vulnerability in D-LINK DWL-6610 access points running firmware version 4.3.0.8B003C. Attackers can ex...

Sep 20, 2023
CVE-2023-43204
9.8

CVE-2023-43204 is a critical command injection vulnerability in D-LINK DWL-6610 access points that allows attackers to execute arbitrary operating sys...

Sep 20, 2023
CVE-2023-43207
9.8

This CVE describes a command injection vulnerability in D-LINK DWL-6610 access points that allows attackers to execute arbitrary commands via the conf...

Sep 20, 2023
CVE-2023-33831
9.8

This is an unauthenticated remote command execution vulnerability in FUXA SCADA/HMI software that allows attackers to execute arbitrary commands on af...

Sep 18, 2023
CVE-2023-39638
9.8

This CVE describes a command injection vulnerability in D-LINK DIR-859 routers that allows remote attackers to execute arbitrary commands on the devic...

Sep 14, 2023
CVE-2023-41011
9.8

This vulnerability allows remote attackers to execute arbitrary commands on China Mobile HG6543C4 home gateways via the shortcut_telnet.cg component. ...

Sep 14, 2023

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,149 CVEs classified as CWE-77, with 443 rated critical and 484 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free