CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,157
Total CVEs
445
Critical
490
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,157)

CVE-2020-19001
9.8

CVE-2020-19001 is a command injection vulnerability in Simiki v1.6.2.1 and earlier that allows remote attackers to execute arbitrary system commands v...

Aug 27, 2021
CVE-2021-39509
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-816 routers through command injection in the web interface. Att...

Aug 24, 2021
CVE-2021-38611
9.8

This CVE describes a command injection vulnerability in NASCENT RemKon Device Manager 4.0.0.0 that allows attackers to execute arbitrary commands with...

Aug 24, 2021
CVE-2020-18758
9.8

This vulnerability in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code on affected programmable logic con...

Aug 13, 2021
CVE-2021-38189
9.8

This vulnerability in the lettre Rust crate allows attackers to inject arbitrary SMTP commands into email message bodies. By placing a period characte...

Aug 8, 2021
CVE-2021-38173
9.8

CVE-2021-38173 is a command injection vulnerability in Btrbk's SSH filtering script that allows authenticated remote users to execute arbitrary comman...

Aug 7, 2021
CVE-2021-36707
9.8

This vulnerability allows remote attackers to execute arbitrary commands on ProLink PRC2402M routers by injecting malicious commands into the led_cmd ...

Aug 6, 2021
CVE-2021-32529
9.8

This is a critical command injection vulnerability in QSAN XEVO and SANOS storage systems that allows remote unauthenticated attackers to execute arbi...

Jul 7, 2021
CVE-2019-25029
9.8

CVE-2019-25029 is a command injection vulnerability in Versa Director that allows attackers to execute arbitrary operating system commands with applic...

May 26, 2021
CVE-2020-28908
9.8

CVE-2020-28908 is a command injection vulnerability in Nagios Fusion 4.1.8 and earlier that allows attackers to execute arbitrary commands with elevat...

May 24, 2021
CVE-2020-28901
9.8

CVE-2020-28901 is a command injection vulnerability in Nagios Fusion that allows attackers to execute arbitrary commands with root privileges. The vul...

May 24, 2021
CVE-2020-20951
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Pluck CMS servers through file upload functionality in the admin panel. It...

May 18, 2021
CVE-2021-25812
9.8

This CVE describes a command injection vulnerability in China Mobile An Lianbao WF-1 routers. Attackers can execute arbitrary commands on the device b...

Apr 29, 2021
CVE-2021-31726
9.8

CVE-2021-31726 is a remote command injection vulnerability in Akuvox C315 devices that allows attackers to execute arbitrary commands via the cfgd_ser...

Apr 25, 2021
CVE-2020-2509
9.8

This is a critical command injection vulnerability (CWE-77) in QNAP QTS and QuTS hero operating systems that allows attackers to execute arbitrary com...

Apr 17, 2021
CVE-2020-27227
9.8

CVE-2020-27227 is an unauthenticated command injection vulnerability in OpenClinic GA that allows remote attackers to execute arbitrary commands on th...

Apr 13, 2021
CVE-2021-26275
9.8

The eslint-fixer package for Node.js contains a command injection vulnerability that allows attackers to execute arbitrary commands on the host system...

Mar 19, 2021
CVE-2020-8298
9.8

CVE-2020-8298 is a command injection vulnerability in the fs-path Node.js module that allows attackers to execute arbitrary commands on the host syste...

Mar 4, 2021
CVE-2021-27185
9.8

CVE-2021-27185 is a command injection vulnerability in the samba-client Node.js package that allows attackers to execute arbitrary commands on the hos...

Feb 10, 2021
CVE-2020-2507
9.8

This is a critical command injection vulnerability in QNAP Helpdesk software that allows remote attackers to execute arbitrary commands on affected sy...

Feb 3, 2021
CVE-2020-17500
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on Barco TransForm N network devices by injecting malicious c...

Jan 7, 2021
CVE-2020-24634
9.8

CVE-2020-24634 is a critical command injection vulnerability in Aruba networking devices that allows remote attackers to execute arbitrary commands by...

Dec 11, 2020
CVE-2019-7198
9.8

CVE-2019-7198 is a command injection vulnerability in QNAP NAS devices that allows attackers to execute arbitrary commands on affected systems. This a...

Dec 10, 2020
CVE-2019-19874
9.8

CVE-2019-19874 is a command injection vulnerability in B&R Industrial Automation APROL web interface that allows attackers to execute arbitrary comman...

Nov 27, 2020
CVE-2019-19872
9.8

CVE-2019-19872 is a command injection vulnerability in B&R Industrial Automation APROL's AprolLoader component that allows attackers to execute arbitr...

Nov 27, 2020
CVE-2020-23639
9.8

This CVE describes a command injection vulnerability in Moxa VPort 461 Series Industrial Video Servers that allows remote attackers to execute arbitra...

Nov 2, 2020
CVE-2018-19950
9.8

This is a critical command injection vulnerability in QNAP Music Station that allows remote attackers to execute arbitrary commands on affected system...

Nov 2, 2020
CVE-2020-11698
9.8

CVE-2020-11698 is a critical command injection vulnerability in SpamTitan's SNMP configuration page that allows remote attackers to execute arbitrary ...

Sep 17, 2020
CVE-2020-8211
9.8

This CVE describes an SQL injection vulnerability in Citrix XenMobile Server that allows attackers to execute arbitrary SQL commands. Affected organiz...

Aug 17, 2020
CVE-2020-8186
9.8

A command injection vulnerability in the devcert module allows attackers to execute arbitrary commands on affected systems when untrusted input is pas...

Jul 10, 2020
CVE-2025-64419
9.6

This vulnerability allows remote command execution as root on Coolify instances when users create applications from malicious repositories using the d...

Jan 5, 2026
CVE-2025-67511
9.6

CVE-2025-67511 is a command injection vulnerability in Cybersecurity AI (CAI) framework versions 0.5.9 and below. Attackers can inject malicious comma...

Dec 11, 2025
CVE-2025-3621
9.6

This critical vulnerability in ActADUR local server allows attackers to execute arbitrary commands on affected systems through multiple weaknesses inc...

Jul 15, 2025
CVE-2024-52325
9.6

ECOVACS robot lawnmowers and vacuums are vulnerable to unauthenticated command injection via Bluetooth Low Energy (BLE) connections. Attackers within ...

Jan 23, 2025
CVE-2024-23624
9.6

An unauthenticated command injection vulnerability in the gena.cgi module of D-Link DAP-1650 devices allows remote attackers to execute arbitrary comm...

Jan 26, 2024
CVE-2021-45626
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects multiple NETGEAR Orbi m...

Dec 26, 2021
CVE-2021-45628
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affec...

Dec 26, 2021
CVE-2021-45632
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects multiple NETGEAR router...

Dec 26, 2021
CVE-2021-45634
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects multiple NETGEAR Orbi a...

Dec 26, 2021
CVE-2021-45621
9.6

CVE-2021-45621 is a critical command injection vulnerability affecting multiple NETGEAR routers, extenders, and WiFi systems. Unauthenticated attacker...

Dec 26, 2021
CVE-2021-45624
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR routers via command injection. It affects multip...

Dec 26, 2021
CVE-2021-45613
9.6

CVE-2021-45613 is a critical command injection vulnerability affecting multiple NETGEAR routers and WiFi systems. Unauthenticated attackers can execut...

Dec 26, 2021
CVE-2021-45615
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injecti...

Dec 26, 2021
CVE-2021-45619
9.6

This CVE allows unauthenticated remote attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It impacts numerous ...

Dec 26, 2021
CVE-2021-45513
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on NETGEAR XR1000 routers. Attackers can gain full control of affect...

Dec 26, 2021
CVE-2021-38530
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR Orbi WiFi systems. It affects multiple RBK, RBR,...

Aug 11, 2021
CVE-2021-38528
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multip...

Aug 11, 2021
CVE-2021-29078
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects multiple Orbi mesh WiFi...

Mar 23, 2021
CVE-2021-29071
9.6

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects mul...

Mar 23, 2021
CVE-2021-29076
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK852, RBK853, RBK854,...

Mar 23, 2021

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,157 CVEs classified as CWE-77, with 445 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free