CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,156)
CVE-2022-26997 is a critical command injection vulnerability in Arris TR3300 routers that allows attackers to execute arbitrary system commands via th...
Mar 15, 2022The Arris TR3300 router contains a command injection vulnerability in its static IP configuration function. Attackers can execute arbitrary system com...
Mar 15, 2022CVE-2022-27001 is a critical command injection vulnerability in Arris TR3300 routers that allows attackers to execute arbitrary system commands via th...
Mar 15, 2022CVE-2022-26995 is a critical command injection vulnerability in Arris TR3300 routers that allows attackers to execute arbitrary system commands via cr...
Mar 15, 2022This vulnerability allows unauthenticated remote attackers to execute arbitrary code as root on TP-Link Tapo C200 IP cameras. It affects cameras runni...
Mar 10, 2022This vulnerability in Honeywell HDZP252DI and HBW2PER1 devices allows attackers to perform ARP cache poisoning, enabling video replay attacks. Attacke...
Feb 24, 2022This CVE describes a command injection vulnerability in TOTOLINK router firmware that allows attackers to execute arbitrary commands via crafted MQTT ...
Feb 19, 2022This is a critical command injection vulnerability in TOTOLINK T6 routers that allows attackers to execute arbitrary commands on affected devices by s...
Feb 19, 2022This is a critical command injection vulnerability in TOTOLINK T6 router firmware that allows attackers to execute arbitrary commands via crafted MQTT...
Feb 19, 2022This CVE describes a command injection vulnerability in TOTOLINK router firmware that allows attackers to execute arbitrary commands via crafted MQTT ...
Feb 19, 2022This CVE describes a command injection vulnerability in Tenda AC10U routers that allows remote attackers to execute arbitrary commands with root privi...
Feb 18, 2022This CVE describes a command injection vulnerability in Tenda G1 and G3 routers that allows attackers to execute arbitrary commands via specific param...
Feb 4, 2022CVE-2022-24148 is a critical command injection vulnerability in Tenda AX3 routers that allows attackers to execute arbitrary system commands via the d...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on Tenda AX3 routers via command injection in the remoteIp parameter. Attacke...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on Tenda G1 and G3 routers by injecting malicious commands into the qvlanIP p...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on Tenda G1 and G3 routers via the dmzHost1 parameter in the formSetDMZ funct...
Feb 4, 2022This CVE describes a command injection vulnerability in D-Link DIR-882 routers that allows attackers to execute arbitrary commands via crafted HNAP1 P...
Feb 4, 2022This CVE describes a command injection vulnerability in D-Link DI-7200GV2.E1 routers that allows attackers to execute arbitrary commands via specific ...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on D-Link DI-7200GV2.E1 routers via command injection in the usb_paswd.asp fu...
Feb 4, 2022This vulnerability in D-Link DI-7200GV2.E1 routers allows attackers to execute arbitrary operating system commands via the url_en parameter in the url...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on D-Link DI-7200GV2.E1 routers via command injection in the msp_info.htm fun...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823-Pro routers via command injection in the SetStaticRouteSett...
Feb 4, 2022This vulnerability allows attackers to execute arbitrary commands on D-Link DIR-823-Pro routers via the station_access_enable parameter in the SetStat...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823-Pro routers via command injection in the samba_name paramet...
Feb 4, 2022CVE-2022-24144 is a critical command injection vulnerability in Tenda AX3 routers that allows attackers to execute arbitrary system commands by manipu...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers by injecting malicious commands into the NTPSyncWi...
Feb 4, 2022This critical vulnerability in TOTOLINK X5000R routers allows attackers to execute arbitrary system commands through the firmware upload function. Att...
Feb 4, 2022This CVE describes a command injection vulnerability in TOTOLINK A720R routers that allows attackers to execute arbitrary commands via the QUERY_STRIN...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on Tenda G1 and G3 routers by injecting malicious commands into the pic_name ...
Feb 4, 2022This CVE describes a command injection vulnerability in Totolink router firmware that allows attackers to execute arbitrary commands via the IpFrom pa...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on affected D-Link DIR-882 routers via a crafted HNAP1 POST request to the tw...
Feb 4, 2022This vulnerability allows remote attackers to execute arbitrary commands on Moxa TN-5900 secure routers through command injection in the firmware. Att...
Jan 26, 2022This CVE describes a command injection vulnerability in the embedded web server of Lexmark devices. Attackers can execute arbitrary commands on affect...
Jan 20, 2022CVE-2021-33963 is a command injection vulnerability in China Mobile An Lianbao WF-1 routers that allows remote attackers to execute arbitrary commands...
Jan 15, 2022Apache Kylin 4.0.0 contains a command injection vulnerability in DiagnosisService where improper validation of project names allows attackers to execu...
Jan 6, 2022This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on TOTOLINK EX200 routers by injecting malicious parameters i...
Jan 4, 2022This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multip...
Dec 26, 2021CVE-2021-43113 is a command injection vulnerability in iTextPDF that allows attackers to execute arbitrary commands on the server by manipulating Ghos...
Dec 15, 2021This critical vulnerability in Digi TransPort devices allows remote attackers with knowledge of the ZING protocol to execute arbitrary commands with S...
Dec 10, 2021This vulnerability allows remote attackers to execute arbitrary commands on Zoho ManageEngine Network Configuration Manager servers due to improper in...
Nov 30, 2021CVE-2021-44079 is a command injection vulnerability in Wazuh's wazuh-slack active response script that allows remote code execution by passing untrust...
Nov 22, 2021CVE-2021-41744 is a critical command injection vulnerability in Yongyou PLM software that allows unauthenticated attackers to execute arbitrary comman...
Oct 22, 2021The shell-quote package for Node.js has a command injection vulnerability due to incorrect regex character class {A-z] instead of {A-Za-z] for Windows...
Oct 21, 2021CVE-2021-42094 is a command injection vulnerability in Zammad that allows attackers to execute arbitrary commands on the server via custom Packages. T...
Oct 7, 2021This vulnerability allows remote attackers to execute arbitrary code on Micro Focus ArcSight ESM systems without authentication. It affects all ArcSig...
Sep 28, 2021This vulnerability allows unauthenticated attackers to execute arbitrary commands on Edgecore ECS2020 devices by sending specially crafted HTTP reques...
Sep 22, 2021This vulnerability allows unauthenticated attackers to execute arbitrary commands on Zoho ManageEngine Desktop Central servers. It affects organizatio...
Sep 21, 2021This vulnerability allows remote attackers to execute arbitrary commands with administrator privileges on Xiaomi AX3600 routers. Attackers can exploit...
Sep 16, 2021CVE-2020-18048 is a command injection vulnerability in CraigMS 1.0 that allows attackers to execute arbitrary commands on the server by entering malic...
Sep 2, 2021This CVE describes a command injection vulnerability in Apache Zeppelin's Spark interpreter settings that allows authenticated users to execute arbitr...
Sep 2, 2021About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,156 CVEs classified as CWE-77, with 444 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free