CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 15 of 83
- CVE-2021-1146HIGHCVSS 7.2EG 7.22021-01-13
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privile…
- CVE-2021-1147HIGHCVSS 7.2EG 7.22021-01-13
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privile…
- CVE-2021-1148HIGHCVSS 7.2EG 7.22021-01-13
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privile…
- CVE-2021-1149HIGHCVSS 7.2EG 7.22021-01-13
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privile…
- CVE-2021-1150HIGHCVSS 7.2EG 7.22021-01-13
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privile…
- CVE-2021-1260HIGHCVSS 7.8EG 7.82021-01-20
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the dev…
- CVE-2021-1261HIGHCVSS 7.8EG 7.82021-01-20
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the dev…
- CVE-2021-1262HIGHCVSS 7.8EG 7.82021-01-20
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the dev…
- CVE-2021-1263HIGHCVSS 7.8EG 7.82021-01-20
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the dev…
- CVE-2021-1298HIGHCVSS 8.8EG 8.82021-01-20
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the dev…
- CVE-2021-1299HIGHCVSS 8.8EG 8.82021-01-20
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the dev…
- CVE-2021-1314HIGHCVSS 7.2EG 7.22021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with …
- CVE-2021-1315HIGHCVSS 7.2EG 7.22021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with …
- CVE-2021-1316HIGHCVSS 7.2EG 7.22021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with …
- CVE-2021-1317HIGHCVSS 7.2EG 7.22021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with …
- CVE-2021-1318HIGHCVSS 7.2EG 7.22021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with …
- CVE-2021-1382MEDIUMCVSS 6.0EG 6.72021-03-24
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root privileges on the underlying operating system. This vulnerability is due to insuf…
- CVE-2021-1384HIGHCVSS 6.5EG 7.42021-03-24
A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating system as the root user. This vulnerability is due to inco…
- CVE-2021-1443HIGHCVSS 5.5EG 7.22021-03-24
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because …
- CVE-2021-1488MEDIUMCVSS 6.7EG 6.72021-04-29
A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root p…
- CVE-2021-1498CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-06
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerab…
- CVE-2021-1514HIGHCVSS 7.8EG 7.82021-05-06
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Administrator privileges on the underlying operating system. This vulnerability is due to ins…
- CVE-2021-1547MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1548MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1549MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1550MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1551MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1552MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1553MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1554MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1555MEDIUMCVSS 4.7EG 4.72021-05-22
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an af…
- CVE-2021-1560HIGHCVSS 6.5EG 7.22021-05-22
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executi…
- CVE-2021-1580HIGHCVSS 6.5EG 7.22021-08-25
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected sys…
- CVE-2021-1594HIGHCVSS 7.5EG 8.12021-10-06
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input v…
- CVE-2021-20122HIGHCVSS 7.2EG 7.22021-10-11
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker connected to the router's LAN and authenti…
- CVE-2021-20159HIGHCVSS 8.8EG 8.82021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command injection as root by supplying a malformed parameter.
- CVE-2021-20160HIGHCVSS 8.8EG 8.82021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the device is vulnerable to command injection …
- CVE-2021-20167HIGHCVSS 8.0EG 8.02021-12-30
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
- CVE-2021-20173HIGHCVSS 8.8EG 8.82021-12-30
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via prec…
- CVE-2021-20527HIGHCVSS 7.2EG 7.22021-04-19
IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759.
- CVE-2021-20698CRITICALCVSS 9.8EG 9.82021-06-07
Sharp NEC Displays (UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it,…
- CVE-2021-20699CRITICALCVSS 9.8EG 9.82021-06-07
Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it…
- CVE-2021-20991CRITICALCVSS 9.8EG 9.82021-04-19
In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.
- CVE-2021-21406MEDIUMCVSS 5.8EG 5.82021-07-21
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in versi…
- CVE-2021-21595MEDIUMCVSS 6.0EG 6.02021-08-16
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM comp…
- CVE-2021-21976HIGHCVSS 7.2EG 7.22021-02-11
vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an authenticated admin user to perform a re…
- CVE-2021-21984CRITICALCVSS 9.8EG 9.82021-05-07
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution …
- CVE-2021-22125HIGHCVSS 6.3EG 7.22021-07-20
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its con…
- CVE-2021-22195HIGHCVSS 8.6EG 8.62021-04-01
Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system
- CVE-2021-22864HIGHCVSS 8.8EG 8.82021-03-23
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and mad…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →