CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,155
Total CVEs
444
Critical
489
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,155)

CVE-2023-27232
9.8

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers that allows attackers to execute arbitrary commands on the device. At...

Mar 28, 2023
CVE-2023-27229
9.8

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers that allows attackers to execute arbitrary commands on the device. At...

Mar 28, 2023
CVE-2023-26800
9.8

This CVE describes a command injection vulnerability in Ruijie Networks RG-EW1200 wireless routers that allows attackers to execute arbitrary commands...

Mar 26, 2023
CVE-2022-28497
9.8

This critical vulnerability in TOTOLink CP900 outdoor CPE devices allows attackers to execute arbitrary commands via command injection in the mtd_writ...

Mar 23, 2023
CVE-2023-27078
9.8

This CVE describes a command injection vulnerability in TP-Link MR3020 routers that allows remote attackers to execute arbitrary commands via crafted ...

Mar 23, 2023
CVE-2023-27224
9.8

CVE-2023-27224 is a command injection vulnerability in Nginx Proxy Manager v2.9.19 that allows attackers to execute arbitrary code via malicious Lua s...

Mar 22, 2023
CVE-2023-22747
9.8

CVE-2023-22747 allows unauthenticated attackers to execute arbitrary commands on Aruba access points by sending malicious packets to UDP port 8211. Th...

Mar 1, 2023
CVE-2023-22749
9.8

CVE-2023-22749 allows unauthenticated attackers to execute arbitrary commands on Aruba access points by sending malicious packets to the PAPI UDP port...

Mar 1, 2023
CVE-2022-48255
9.8

This is a critical command injection vulnerability in Huawei BiSheng-WNM firmware that allows attackers to execute arbitrary system commands on affect...

Feb 27, 2023
CVE-2023-23080
9.8

This vulnerability allows remote attackers to execute arbitrary commands on affected Tenda products via command injection. It affects multiple Tenda c...

Feb 27, 2023
CVE-2023-26602
9.8

This vulnerability in ASUS ASMB8 iKVM firmware allows remote attackers to execute arbitrary code via SNMP commands that create malicious extensions. A...

Feb 26, 2023
CVE-2023-25805
9.8

CVE-2023-25805 is a command injection vulnerability in versionn software that allows attackers to execute arbitrary commands on the system. All users ...

Feb 20, 2023
CVE-2022-40021
9.8

This CVE describes a command injection vulnerability in QVidium Technologies Amino A140 devices running firmware versions prior to 1.0.0-283. Attacker...

Feb 17, 2023
CVE-2023-24236
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink A7100RU routers by injecting malicious commands into the province...

Feb 16, 2023
CVE-2023-24159
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the admpas...

Feb 14, 2023
CVE-2023-24161
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands through the web...

Feb 14, 2023
CVE-2022-40022
9.8

CVE-2022-40022 is a critical command injection vulnerability in Microchip Technology SyncServer S650 network time servers that allows unauthenticated ...

Feb 13, 2023
CVE-2021-31573
9.8

CVE-2021-31573 is a command injection vulnerability in MediaTek Config Manager that allows remote attackers to execute arbitrary commands without auth...

Feb 6, 2023
CVE-2021-31575
9.8

CVE-2021-31575 is a command injection vulnerability in MediaTek's Config Manager that allows remote attackers to execute arbitrary commands without au...

Feb 6, 2023
CVE-2023-23333
9.8

CVE-2023-23333 is a critical command injection vulnerability in SolarView Compact versions up to 6.00 that allows remote attackers to execute arbitrar...

Feb 6, 2023
CVE-2023-24152
9.8

This critical vulnerability in TOTOLINK T8 routers allows remote attackers to execute arbitrary commands by sending specially crafted MQTT packets to ...

Feb 3, 2023
CVE-2023-24154
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK T8 routers via command injection in the slaveIpList parameter of ...

Feb 3, 2023
CVE-2023-24156
9.8

This critical vulnerability in TOTOLINK T8 routers allows remote attackers to execute arbitrary commands by sending specially crafted MQTT packets to ...

Feb 3, 2023
CVE-2023-24148
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the FileNa...

Feb 3, 2023
CVE-2023-24150
9.8

This CVE describes a command injection vulnerability in TOTOLINK T8 routers that allows attackers to execute arbitrary commands via crafted MQTT packe...

Feb 3, 2023
CVE-2023-24142
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the NetDia...

Feb 3, 2023
CVE-2023-24144
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the hour p...

Feb 3, 2023
CVE-2023-24146
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious commands into the minute...

Feb 3, 2023
CVE-2023-24138
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers via command injection in the NTPSyncWithHost fu...

Feb 3, 2023
CVE-2023-24140
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK CA300-PoE routers by injecting malicious input into the NetDiagPi...

Feb 3, 2023
CVE-2016-4991
9.8

CVE-2016-4991 is a command injection vulnerability in nodepdf's PDF rendering function. Attackers can inject shell commands through specially crafted ...

Jul 28, 2022
CVE-2020-28438
9.8

CVE-2020-28438 is a command injection vulnerability in the deferred-exec npm package that allows attackers to execute arbitrary commands on the host s...

Jul 25, 2022
CVE-2020-28443
9.8

CVE-2020-28443 is a command injection vulnerability in the sonar-wrapper npm package that allows attackers to execute arbitrary commands on the host s...

Jul 25, 2022
CVE-2020-28446
9.8

CVE-2020-28446 is a command injection vulnerability in the ntesseract npm package that allows attackers to execute arbitrary commands on the host syst...

Jul 25, 2022
CVE-2022-2143
9.8

CVE-2022-2143 is a critical command injection vulnerability in Advantech iView NetworkServlet that allows remote attackers to execute arbitrary code o...

Jul 22, 2022
CVE-2022-32449
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK EX300_V2 routers by sending specially crafted MQTT packets contai...

Jul 7, 2022
CVE-2022-34592
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink WL-WN575A3 routers via a crafted POST request to the obtw function...

Jul 7, 2022
CVE-2022-31874
9.8

This vulnerability allows remote attackers to execute arbitrary commands on ASUS RT-N53 routers by injecting malicious commands into the SystemCmd par...

Jun 17, 2022
CVE-2022-29712
9.8

CVE-2022-29712 allows remote attackers to execute arbitrary commands on LibreNMS servers through command injection vulnerabilities in service_ip, host...

Jun 2, 2022
CVE-2022-28618
9.8

This CVE-2022-28618 is a critical command injection vulnerability in HPE Nimble Storage arrays that allows attackers to execute arbitrary commands on ...

May 20, 2022
CVE-2022-27588
9.8

CVE-2022-27588 is a critical command injection vulnerability in QNAP QVR software that allows attackers to execute arbitrary commands on affected syst...

May 5, 2022
CVE-2021-43163
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Ruijie Networks RG-EW series routers via the checkNet function...

May 4, 2022
CVE-2021-23247
9.8

CVE-2021-23247 is a command injection vulnerability in the Quick Game Engine that allows remote attackers to execute arbitrary code on affected system...

Apr 1, 2022
CVE-2022-27076
9.8

CVE-2022-27076 is a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. This affect...

Mar 24, 2022
CVE-2022-27078
9.8

This CVE describes a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. The vulner...

Mar 24, 2022
CVE-2022-27080
9.8

CVE-2022-27080 is a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. This affect...

Mar 24, 2022
CVE-2022-27082
9.8

CVE-2022-27082 is a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. This affect...

Mar 24, 2022
CVE-2022-26186
9.8

CVE-2022-26186 is a command injection vulnerability in TOTOLINK N600R routers that allows attackers to execute arbitrary commands on the device via th...

Mar 22, 2022
CVE-2022-26188
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK N600R routers via the NTPSyncWithHost setting. Attackers can gain...

Mar 22, 2022
CVE-2021-45876
9.8

CVE-2021-45876 allows unauthenticated attackers to execute arbitrary commands on GARO Wallbox charging stations by injecting malicious code into the f...

Mar 21, 2022

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,155 CVEs classified as CWE-77, with 444 rated critical and 489 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free