CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 21 of 83
- CVE-2021-43118CRITICALCVSS 9.8EG 9.82022-03-29
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a r…
- CVE-2021-43159HIGHCVSS 8.8EG 8.82022-05-04
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..
- CVE-2021-43160HIGHCVSS 8.8EG 8.82022-05-04
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.
- CVE-2021-43161HIGHCVSS 8.8EG 8.82022-05-04
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.
- CVE-2021-43162HIGHCVSS 8.8EG 8.82022-05-04
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.
- CVE-2021-43163CRITICALCVSS 9.8EG 9.82022-05-04
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.
- CVE-2021-43164HIGHCVSS 8.8EG 8.82022-05-04
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.
- CVE-2021-43266HIGHCVSS 7.3EG 7.32021-11-02
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting…
- CVE-2021-43286HIGHCVSS 8.8EG 8.82022-04-14
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.
- CVE-2021-4329MEDIUMCVSS 5.5EG 5.52023-03-05
A vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0. Affected by this issue is some unknown functionality of the file logic.js. The manipulation leads to command injection. Upgrading to version 2.0.1 is…
- CVE-2021-43319CRITICALCVSS 9.8EG 9.82021-11-30
Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.
- CVE-2021-43339HIGHCVSS 8.8EG 8.82021-11-03
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.
- CVE-2021-43469HIGHCVSS 8.8EG 8.82021-12-06
VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.
- CVE-2021-43474CRITICALCVSS 9.8EG 9.82022-04-07
An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function
- CVE-2021-43557HIGHCVSS 7.5EG 7.52021-11-22
The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some…
- CVE-2021-43589MEDIUMCVSS 6.0EG 6.02022-01-24
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially exploit this vulner…
- CVE-2021-43663HIGHCVSS 7.5EG 7.52022-03-31
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.
- CVE-2021-43664HIGHCVSS 8.1EG 8.12022-03-30
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.
- CVE-2021-43711CRITICALCVSS 9.8EG 9.82022-01-04
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.
- CVE-2021-44051HIGHCVSS 8.8EG 8.82022-05-05
A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in th…
- CVE-2021-4406CRITICALCVSS 9.1EG 9.12023-07-10
An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #'…
- CVE-2021-44079CRITICALCVSS 9.8EG 9.82021-11-22
In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.
- CVE-2021-44132HIGHCVSS 7.8EG 7.82022-02-25
A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file.
- CVE-2021-44247CRITICALCVSS 9.8EG 9.82022-02-04
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to e…
- CVE-2021-44520HIGHCVSS 8.8EG 8.82022-04-13
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
- CVE-2021-44620CRITICALCVSS 9.8EG 9.82022-03-11
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.
- CVE-2021-44735CRITICALCVSS 9.8EG 9.82022-01-20
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
- CVE-2021-44880CRITICALCVSS 9.8EG 9.82022-02-04
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary comman…
- CVE-2021-44881CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
- CVE-2021-44882CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
- CVE-2021-45082HIGHCVSS 7.8EG 7.82022-02-19
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are…
- CVE-2021-45382CRITICALCVSS 9.8EG 9.8⚠ KEV2022-02-17
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826…
- CVE-2021-45401CRITICALCVSS 9.8EG 9.82022-02-18
A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client controlled "deviceName…
- CVE-2021-45441HIGHCVSS 7.8EG 7.82022-01-10
A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher level of privileges.…
- CVE-2021-45456CRITICALCVSS 9.8EG 9.82022-01-06
Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in Diagnos…
- CVE-2021-45459CRITICALCVSS 9.8EG 9.82021-12-22
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
- CVE-2021-45513CRITICALCVSS 9.6EG 9.62021-12-26
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
- CVE-2021-45514CRITICALCVSS 9.6EG 9.62021-12-26
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
- CVE-2021-45531HIGHCVSS 7.1EG 7.12021-12-26
NETGEAR D6220 devices before 1.0.0.76 are affected by command injection by an authenticated user.
- CVE-2021-45532MEDIUMCVSS 6.7EG 6.72021-12-26
NETGEAR R8000 devices before 1.0.4.76 are affected by command injection by an authenticated user.
- CVE-2021-45533HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects EX6120 before 1.0.0.66, EX6130 before 1.0.0.46, EX7000 before 1.0.1.106, EX7500 before 1.0.1.76, EX3700 before 1.0.0.94, EX3800 before 1.0.0.9…
- CVE-2021-45534HIGHCVSS 7.8EG 7.82021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects AC2100 before 1.2.0.88, AC2400 before 1.2.0.88, AC2600 before 1.2.0.88, D7000 before 1.0.1.82, R6220 before 1.1.0.110, R6230 before 1.1.0.110,…
- CVE-2021-45535HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.3.106, RAX80 before 1.0.3.106, RAX75 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.…
- CVE-2021-45536HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6…
- CVE-2021-45537HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user . This affects RAX200 before 1.0.3.106, RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16…
- CVE-2021-45538HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6…
- CVE-2021-45539HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000 before 1.0.4.74, R8000P before 1.4.2.84, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, R…
- CVE-2021-45540HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126, R7900 before 1.0.4.46, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000 before 1.0.4.74, R8000P before 1.4.2.84,…
- CVE-2021-45541HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900 before 1.0.4.38, R7900P before 1.4.2.84, R8000 before 1.0.4.68, R8000P before 1.4.2.84, RAX200 before 1.0.3.106, MR60 before 1.0.6.110, …
- CVE-2021-45542HIGHCVSS 8.4EG 8.42021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →