CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,151
Total CVEs
443
Critical
486
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 18
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,151)

CVE-2023-39637
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-816 A2 routers via the /goform/Diagnosis component. Attackers c...

Sep 12, 2023
CVE-2023-39617
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected TOTOLINK X5000R routers by sending specially crafted requests to the ...

Aug 21, 2023
CVE-2023-39809
9.8

This vulnerability allows remote attackers to execute arbitrary commands on NVK iBSG v3.5 systems by injecting malicious commands into the system_host...

Aug 21, 2023
CVE-2023-38866
9.8

COMFAST CF-XR11 V2.7.2 contains a command injection vulnerability in the web management interface. Attackers can send specially crafted POST requests ...

Aug 15, 2023
CVE-2023-38861
9.8

This vulnerability allows remote attackers to execute arbitrary code on Wavlink WL_WNJ575A3 routers by exploiting improper input validation in the use...

Aug 15, 2023
CVE-2023-38863
9.8

This is a command injection vulnerability in COMFAST CF-XR11 routers that allows remote attackers to execute arbitrary commands on the device. Attacke...

Aug 15, 2023
CVE-2023-39293
9.8

This critical command injection vulnerability in MiVoice Office 400 SMB Controller allows attackers to execute arbitrary system commands with the priv...

Aug 14, 2023
CVE-2023-39001
9.8

This CVE describes a command injection vulnerability in OPNsense's diag_backup.php component that allows attackers to execute arbitrary commands by up...

Aug 9, 2023
CVE-2023-38928
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Netgear R7100LG routers by injecting malicious code into the password para...

Aug 7, 2023
CVE-2023-38941
9.8

This vulnerability allows remote attackers to execute arbitrary commands on servers running django-sspanel v2022.2.2 through the GoodsCreateView compo...

Aug 4, 2023
CVE-2023-38942
9.8

Dango-Translator v4.5.5 contains a remote command execution vulnerability via the cloud_config.json configuration file. Attackers can execute arbitrar...

Aug 3, 2023
CVE-2022-39986
9.8

CVE-2022-39986 is an unauthenticated command injection vulnerability in RaspAP web interface versions 2.8.0 through 2.8.7. Attackers can execute arbit...

Aug 1, 2023
CVE-2023-34960
9.8

A critical command injection vulnerability in Chamilo's wsConvertPpt component allows remote attackers to execute arbitrary commands on the server via...

Aug 1, 2023
CVE-2023-37214
9.8

CVE-2023-37214 is a command injection vulnerability in Heights Telecom ERO1xS-Pro Dual-Band firmware that allows attackers to execute arbitrary comman...

Jul 30, 2023
CVE-2023-38336
9.8

CVE-2023-38336 is a command injection vulnerability in netkit-rcp (part of rsh-client) that allows attackers to execute arbitrary commands via special...

Jul 14, 2023
CVE-2023-37567
9.8

A critical command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows remote unauthenticated attackers to execute arbitrary com...

Jul 13, 2023
CVE-2023-37144
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC10 routers by injecting malicious commands into the mac parameter ...

Jul 7, 2023
CVE-2023-37146
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK LR350 routers by injecting malicious commands into the FileName p...

Jul 7, 2023
CVE-2023-37149
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK LR350 routers by injecting malicious commands into the FileName p...

Jul 7, 2023
CVE-2023-27836
9.8

This CVE describes a command injection vulnerability in TP-Link TL-WPA8630P powerline Wi-Fi extenders. Attackers can execute arbitrary commands on the...

Jun 13, 2023
CVE-2023-27837
9.8

This CVE describes a command injection vulnerability in TP-Link TL-WPA8630P powerline Wi-Fi extenders. Attackers can execute arbitrary commands on the...

Jun 13, 2023
CVE-2023-26295
9.8

CVE-2023-26295 is a command injection vulnerability in HP Device Manager that allows attackers to execute arbitrary commands on affected systems. This...

Jun 12, 2023
CVE-2023-33556
9.8

This CVE describes a command injection vulnerability in TOTOLink A7100RU routers that allows attackers to execute arbitrary commands on the device. Th...

Jun 7, 2023
CVE-2023-20887
9.8

CVE-2023-20887 is a command injection vulnerability in VMware Aria Operations for Networks that allows remote code execution. Attackers with network a...

Jun 7, 2023
CVE-2023-30400
9.8

This CVE describes a command injection vulnerability in Anyka Microelectronics AK3918EV300 MCU firmware version 18. Attackers can execute arbitrary co...

Jun 7, 2023
CVE-2023-31569
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers via command injection in the setWanCfg function. A...

Jun 6, 2023
CVE-2023-33532
9.8

This CVE describes a command injection vulnerability in Netgear R6250 routers that allows authenticated attackers to execute arbitrary commands with s...

Jun 6, 2023
CVE-2023-23952
9.8

This CVE describes a command injection vulnerability in Broadcom's Advanced Secure Gateway and Content Analysis products. Attackers can execute arbitr...

Jun 1, 2023
CVE-2015-20108
9.8

This vulnerability in the ruby-saml gem allows XPath injection leading to remote code execution. Attackers can execute arbitrary code on systems using...

May 27, 2023
CVE-2023-33294
9.8

CVE-2023-33294 is a critical remote code execution vulnerability in KaiOS 3.0 where an exposed local web server on port 2929 allows arbitrary bash com...

May 22, 2023
CVE-2023-31729
9.8

CVE-2023-31729 is a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device via t...

May 18, 2023
CVE-2023-31856
9.8

This CVE describes a command injection vulnerability in TOTOLINK CP300+ routers that allows attackers to execute arbitrary commands via crafted HTTP p...

May 16, 2023
CVE-2023-31986
9.8

A command injection vulnerability in Edimax N300 router firmware allows unauthenticated attackers to execute arbitrary system commands via the setWAN ...

May 15, 2023
CVE-2023-31983
9.8

This CVE describes a critical command injection vulnerability in Edimax N300 wireless router firmware that allows unauthenticated attackers to execute...

May 12, 2023
CVE-2023-24540
9.8

This CVE describes a template injection vulnerability in Go's text/template and html/template packages where certain Unicode whitespace characters are...

May 11, 2023
CVE-2023-30135
9.8

This CVE describes a command injection vulnerability in Tenda AC18 routers that allows attackers to execute arbitrary commands on the device. Attacker...

May 5, 2023
CVE-2023-27849
9.8

CVE-2023-27849 is a critical remote code execution vulnerability in rails-routes-to-json v1.0.0 that allows attackers to execute arbitrary commands on...

Apr 24, 2023
CVE-2023-29566
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of huedawn-tesseract or dawnsparks-node-te...

Apr 24, 2023
CVE-2022-46640
9.8

The Nanoleaf Desktop App before version 1.3.1 contains a command injection vulnerability that allows attackers to execute arbitrary commands on affect...

Apr 18, 2023
CVE-2023-29800
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X18 routers by injecting malicious commands into the FileName par...

Apr 14, 2023
CVE-2023-29802
9.8

This CVE describes a command injection vulnerability in TOTOLINK X18 routers that allows attackers to execute arbitrary commands on the device by mani...

Apr 14, 2023
CVE-2023-29798
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X18 routers by injecting malicious commands into the setTracerout...

Apr 14, 2023
CVE-2023-28489
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on Siemens CP-8031 and CP-8050 MASTER MODULE devices via comm...

Apr 11, 2023
CVE-2023-26848
9.8

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers via the org parameter in the setting/delStaticDhcpRules endpoint, all...

Apr 7, 2023
CVE-2023-29474
9.8

This critical vulnerability in Atos Unify OpenScape 4000 platforms allows unauthenticated attackers to execute arbitrary operating system commands and...

Apr 6, 2023
CVE-2023-1877
9.8

This CVE describes a command injection vulnerability in Microweber CMS versions prior to 1.3.3. Attackers can execute arbitrary operating system comma...

Apr 5, 2023
CVE-2023-26866
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on GreenPacket OH736 WR-1200 Indoor Unit...

Apr 4, 2023
CVE-2023-1671
9.8

CVE-2023-1671 is a critical pre-authentication command injection vulnerability in Sophos Web Appliance that allows unauthenticated attackers to execut...

Apr 4, 2023
CVE-2023-28677
9.8

This vulnerability in Jenkins Convert To Pipeline Plugin allows attackers with permission to configure Freestyle projects to inject malicious Pipeline...

Apr 2, 2023
CVE-2023-26822
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link Go-RT-AC750 routers via command injection in the service parameter ...

Apr 1, 2023

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,151 CVEs classified as CWE-77, with 443 rated critical and 486 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free