CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 19 of 83
- CVE-2021-34748HIGHCVSS 8.8EG 8.82021-10-06
A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficien…
- CVE-2021-34756HIGHCVSS 6.7EG 7.82021-10-27
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the…
- CVE-2021-34809CRITICALCVSS 9.9EG 9.92021-06-18
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via …
- CVE-2021-35049CRITICALCVSS 9.9EG 9.92021-06-25
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and …
- CVE-2021-3515MEDIUMCVSS 6.7EG 6.72021-06-01
A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user …
- CVE-2021-35220HIGHCVSS 8.1EG 8.12021-08-31
Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
- CVE-2021-35394CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-16
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command inje…
- CVE-2021-35395CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-16
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs a…
- CVE-2021-35978CRITICALCVSS 9.8EG 9.82021-12-10
An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the…
- CVE-2021-36024CRITICALCVSS 9.1EG 9.12021-09-01
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Improper Neutralization of Special Elements Used In A Command via the Data collection endpoint. An attacker with admin privile…
- CVE-2021-36100HIGHCVSS 6.4EG 8.82022-03-21
Specially crafted string in OTRS system configuration can allow the execution of any system command.
- CVE-2021-3617HIGHCVSS 7.2EG 7.22021-08-17
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configuration. This vulnerability is the same as CNVD-2020-68652.
- CVE-2021-36180HIGHCVSS 8.1EG 8.82021-12-08
Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to execute unauthorized…
- CVE-2021-3621HIGHCVSS 8.8EG 8.82021-12-23
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl comma…
- CVE-2021-36260CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-22
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious co…
- CVE-2021-36705CRITICALCVSS 9.8EG 9.82021-08-06
In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivial command injection where the value of the TR069_local_port parameter is passed directly …
- CVE-2021-36706CRITICALCVSS 9.8EG 9.82021-08-06
In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to sys…
- CVE-2021-36707CRITICALCVSS 9.8EG 9.82021-08-06
In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to …
- CVE-2021-37102HIGHCVSS 8.8EG 8.82021-11-23
There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software doe…
- CVE-2021-37106HIGHCVSS 7.2EG 7.22021-09-28
There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users…
- CVE-2021-37145HIGHCVSS 7.2EG 7.22021-09-07
A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privilege Escalation and Remote Code Execution capability. NOTE: This vulnerability only affect…
- CVE-2021-37708HIGHCVSS 8.8EG 8.82021-08-16
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, correspond…
- CVE-2021-37717HIGHCVSS 7.2EG 7.22021-09-07
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has release…
- CVE-2021-37718HIGHCVSS 7.2EG 7.22021-09-07
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.6; Prior to 8.7.1.4, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has release…
- CVE-2021-37719HIGHCVSS 7.2EG 7.22021-09-07
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.2…
- CVE-2021-37720HIGHCVSS 7.2EG 7.22021-09-07
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.2…
- CVE-2021-37721HIGHCVSS 7.2EG 7.22021-09-07
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.2…
- CVE-2021-37722HIGHCVSS 7.2EG 7.22021-09-07
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.7.1.4, 8.6.0.9, 8.5.0.13, 8.3.0.16, 6.5.4.20, 6.4.4.2…
- CVE-2021-37723HIGHCVSS 7.2EG 7.22021-09-07
A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability.
- CVE-2021-37724HIGHCVSS 7.2EG 7.22021-09-07
A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.16. Aruba has released patches for ArubaOS that address this security vulnerability.
- CVE-2021-37739HIGHCVSS 7.2EG 7.22021-10-15
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Mana…
- CVE-2021-38116HIGHCVSS 8.8EG 8.82024-11-22
Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5
- CVE-2021-38117HIGHCVSS 8.8EG 8.82024-11-22
Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
- CVE-2021-38120MEDIUMCVSS 5.1EG 5.12024-08-28
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authent…
- CVE-2021-38124CRITICALCVSS 9.8EG 9.82021-09-28
Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution.
- CVE-2021-38169HIGHCVSS 8.8EG 8.82021-08-07
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
- CVE-2021-38173CRITICALCVSS 9.8EG 9.82021-08-07
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
- CVE-2021-38189CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands.
- CVE-2021-38370MEDIUMCVSS 5.9EG 5.92021-08-10
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
- CVE-2021-38372LOWCVSS 3.7EG 3.72021-08-10
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.
- CVE-2021-38373MEDIUMCVSS 5.3EG 5.32021-08-10
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
- CVE-2021-38510HIGHCVSS 8.8EG 8.82021-12-08
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaf…
- CVE-2021-38518HIGHCVSS 8.4EG 8.42021-08-11
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3…
- CVE-2021-38519MEDIUMCVSS 6.3EG 6.32021-08-11
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6700 before 1.0.2.8,…
- CVE-2021-38520MEDIUMCVSS 6.6EG 6.62021-08-11
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, and R7000P before 1…
- CVE-2021-38521MEDIUMCVSS 6.1EG 6.12021-08-11
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50, R7900P before 1.4.1.50, R8000P before 1.4.1.50, RAX75 before 1.0.1.62, and RAX80 before 1.0.1.62.
- CVE-2021-38527HIGHCVSS 8.1EG 8.12021-08-11
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.98, EX6150v2 before 1.0.1.98, EX6250 before 1.0.0.132, EX6400 before 1.0.2.158, EX6400v2 be…
- CVE-2021-38528CRITICALCVSS 9.6EG 9.62021-08-11
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1.0.1.38, and XR300 …
- CVE-2021-38529HIGHCVSS 8.3EG 8.32021-08-11
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.
- CVE-2021-38530CRITICALCVSS 9.6EG 9.62021-08-11
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →