CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,156
Total CVEs
444
Critical
490
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,156)

CVE-2022-26997
9.8

CVE-2022-26997 is a critical command injection vulnerability in Arris TR3300 routers that allows attackers to execute arbitrary system commands via th...

Mar 15, 2022
CVE-2022-26999
9.8

The Arris TR3300 router contains a command injection vulnerability in its static IP configuration function. Attackers can execute arbitrary system com...

Mar 15, 2022
CVE-2022-27001
9.8

CVE-2022-27001 is a critical command injection vulnerability in Arris TR3300 routers that allows attackers to execute arbitrary system commands via th...

Mar 15, 2022
CVE-2022-26995
9.8

CVE-2022-26995 is a critical command injection vulnerability in Arris TR3300 routers that allows attackers to execute arbitrary system commands via cr...

Mar 15, 2022
CVE-2021-4045
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code as root on TP-Link Tapo C200 IP cameras. It affects cameras runni...

Mar 10, 2022
CVE-2021-39363
9.8

This vulnerability in Honeywell HDZP252DI and HBW2PER1 devices allows attackers to perform ARP cache poisoning, enabling video replay attacks. Attacke...

Feb 24, 2022
CVE-2022-25130
9.8

This CVE describes a command injection vulnerability in TOTOLINK router firmware that allows attackers to execute arbitrary commands via crafted MQTT ...

Feb 19, 2022
CVE-2022-25132
9.8

This is a critical command injection vulnerability in TOTOLINK T6 routers that allows attackers to execute arbitrary commands on affected devices by s...

Feb 19, 2022
CVE-2022-25134
9.8

This is a critical command injection vulnerability in TOTOLINK T6 router firmware that allows attackers to execute arbitrary commands via crafted MQTT...

Feb 19, 2022
CVE-2022-25136
9.8

This CVE describes a command injection vulnerability in TOTOLINK router firmware that allows attackers to execute arbitrary commands via crafted MQTT ...

Feb 19, 2022
CVE-2021-45401
9.8

This CVE describes a command injection vulnerability in Tenda AC10U routers that allows remote attackers to execute arbitrary commands with root privi...

Feb 18, 2022
CVE-2022-24170
9.8

This CVE describes a command injection vulnerability in Tenda G1 and G3 routers that allows attackers to execute arbitrary commands via specific param...

Feb 4, 2022
CVE-2022-24148
9.8

CVE-2022-24148 is a critical command injection vulnerability in Tenda AX3 routers that allows attackers to execute arbitrary system commands via the d...

Feb 4, 2022
CVE-2022-24150
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AX3 routers via command injection in the remoteIp parameter. Attacke...

Feb 4, 2022
CVE-2022-24165
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda G1 and G3 routers by injecting malicious commands into the qvlanIP p...

Feb 4, 2022
CVE-2022-24167
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda G1 and G3 routers via the dmzHost1 parameter in the formSetDMZ funct...

Feb 4, 2022
CVE-2021-45998
9.8

This CVE describes a command injection vulnerability in D-Link DIR-882 routers that allows attackers to execute arbitrary commands via crafted HNAP1 P...

Feb 4, 2022
CVE-2021-46227
9.8

This CVE describes a command injection vulnerability in D-Link DI-7200GV2.E1 routers that allows attackers to execute arbitrary commands via specific ...

Feb 4, 2022
CVE-2021-46229
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DI-7200GV2.E1 routers via command injection in the usb_paswd.asp fu...

Feb 4, 2022
CVE-2021-46231
9.8

This vulnerability in D-Link DI-7200GV2.E1 routers allows attackers to execute arbitrary operating system commands via the url_en parameter in the url...

Feb 4, 2022
CVE-2021-46233
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DI-7200GV2.E1 routers via command injection in the msp_info.htm fun...

Feb 4, 2022
CVE-2021-46453
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823-Pro routers via command injection in the SetStaticRouteSett...

Feb 4, 2022
CVE-2021-46455
9.8

This vulnerability allows attackers to execute arbitrary commands on D-Link DIR-823-Pro routers via the station_access_enable parameter in the SetStat...

Feb 4, 2022
CVE-2021-46457
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823-Pro routers via command injection in the samba_name paramet...

Feb 4, 2022
CVE-2022-24144
9.8

CVE-2022-24144 is a critical command injection vulnerability in Tenda AX3 routers that allows attackers to execute arbitrary system commands by manipu...

Feb 4, 2022
CVE-2021-45733
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers by injecting malicious commands into the NTPSyncWi...

Feb 4, 2022
CVE-2021-45738
9.8

This critical vulnerability in TOTOLINK X5000R routers allows attackers to execute arbitrary system commands through the firmware upload function. Att...

Feb 4, 2022
CVE-2021-45742
9.8

This CVE describes a command injection vulnerability in TOTOLINK A720R routers that allows attackers to execute arbitrary commands via the QUERY_STRIN...

Feb 4, 2022
CVE-2021-45990
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda G1 and G3 routers by injecting malicious commands into the pic_name ...

Feb 4, 2022
CVE-2021-44247
9.8

This CVE describes a command injection vulnerability in Totolink router firmware that allows attackers to execute arbitrary commands via the IpFrom pa...

Feb 4, 2022
CVE-2021-44881
9.8

This vulnerability allows remote attackers to execute arbitrary commands on affected D-Link DIR-882 routers via a crafted HNAP1 POST request to the tw...

Feb 4, 2022
CVE-2021-46560
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Moxa TN-5900 secure routers through command injection in the firmware. Att...

Jan 26, 2022
CVE-2021-44735
9.8

This CVE describes a command injection vulnerability in the embedded web server of Lexmark devices. Attackers can execute arbitrary commands on affect...

Jan 20, 2022
CVE-2021-33963
9.8

CVE-2021-33963 is a command injection vulnerability in China Mobile An Lianbao WF-1 routers that allows remote attackers to execute arbitrary commands...

Jan 15, 2022
CVE-2021-45456
9.8

Apache Kylin 4.0.0 contains a command injection vulnerability in DiagnosisService where improper validation of project names allows attackers to execu...

Jan 6, 2022
CVE-2021-43711
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on TOTOLINK EX200 routers by injecting malicious parameters i...

Jan 4, 2022
CVE-2021-45617
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multip...

Dec 26, 2021
CVE-2021-43113
9.8

CVE-2021-43113 is a command injection vulnerability in iTextPDF that allows attackers to execute arbitrary commands on the server by manipulating Ghos...

Dec 15, 2021
CVE-2021-35978
9.8

This critical vulnerability in Digi TransPort devices allows remote attackers with knowledge of the ZING protocol to execute arbitrary commands with S...

Dec 10, 2021
CVE-2021-43319
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Zoho ManageEngine Network Configuration Manager servers due to improper in...

Nov 30, 2021
CVE-2021-44079
9.8

CVE-2021-44079 is a command injection vulnerability in Wazuh's wazuh-slack active response script that allows remote code execution by passing untrust...

Nov 22, 2021
CVE-2021-41744
9.8

CVE-2021-41744 is a critical command injection vulnerability in Yongyou PLM software that allows unauthenticated attackers to execute arbitrary comman...

Oct 22, 2021
CVE-2021-42740
9.8

The shell-quote package for Node.js has a command injection vulnerability due to incorrect regex character class {A-z] instead of {A-Za-z] for Windows...

Oct 21, 2021
CVE-2021-42094
9.8

CVE-2021-42094 is a command injection vulnerability in Zammad that allows attackers to execute arbitrary commands on the server via custom Packages. T...

Oct 7, 2021
CVE-2021-38124
9.8

This vulnerability allows remote attackers to execute arbitrary code on Micro Focus ArcSight ESM systems without authentication. It affects all ArcSig...

Sep 28, 2021
CVE-2019-6288
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on Edgecore ECS2020 devices by sending specially crafted HTTP reques...

Sep 22, 2021
CVE-2021-28960
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on Zoho ManageEngine Desktop Central servers. It affects organizatio...

Sep 21, 2021
CVE-2020-14119
9.8

This vulnerability allows remote attackers to execute arbitrary commands with administrator privileges on Xiaomi AX3600 routers. Attackers can exploit...

Sep 16, 2021
CVE-2020-18048
9.8

CVE-2020-18048 is a command injection vulnerability in CraigMS 1.0 that allows attackers to execute arbitrary commands on the server by entering malic...

Sep 2, 2021
CVE-2019-10095
9.8

This CVE describes a command injection vulnerability in Apache Zeppelin's Spark interpreter settings that allows authenticated users to execute arbitr...

Sep 2, 2021

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,156 CVEs classified as CWE-77, with 444 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free