CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 30 of 83
- CVE-2022-36485HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
- CVE-2022-36486HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
- CVE-2022-36487HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.
- CVE-2022-36509HIGHCVSS 7.8EG 7.82022-08-25
H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
- CVE-2022-36510HIGHCVSS 7.8EG 7.82022-08-25
H3C GR2200 MiniGR1A0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
- CVE-2022-36523CRITICALCVSS 9.8EG 9.82022-08-15
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
- CVE-2022-36534HIGHCVSS 8.8EG 8.92022-09-16
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.p…
- CVE-2022-36553CRITICALCVSS 9.8EG 9.82022-08-29
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
- CVE-2022-36554CRITICALCVSS 9.8EG 9.82022-08-29
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.
- CVE-2022-36556CRITICALCVSS 9.8EG 9.82022-08-29
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.
- CVE-2022-36559CRITICALCVSS 9.8EG 9.82022-08-29
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.
- CVE-2022-36749CRITICALCVSS 9.8EG 9.82022-08-30
RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.
- CVE-2022-36756CRITICALCVSS 9.8EG 9.82022-08-28
DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
- CVE-2022-36768HIGHCVSS 7.8EG 7.82022-09-13
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to obtain root privileges. IBM X-Force ID: 232014.
- CVE-2022-36769HIGHCVSS 7.2EG 7.22023-04-26
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.
- CVE-2022-36786CRITICALCVSS 9.9EG 9.92022-11-17
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permi…
- CVE-2022-36804CRITICALCVSS 8.8EG 9.0⚠ KEV2022-08-25
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8…
- CVE-2022-36962HIGHCVSS 7.2EG 7.22022-11-29
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands.
- CVE-2022-37053CRITICALCVSS 9.8EG 9.82022-08-28
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
- CVE-2022-37056CRITICALCVSS 9.8EG 9.82022-08-28
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,
- CVE-2022-37057CRITICALCVSS 9.8EG 9.82022-08-28
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.
- CVE-2022-37070CRITICALCVSS 9.8EG 9.82022-08-25
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
- CVE-2022-37076HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
- CVE-2022-37078HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.
- CVE-2022-37079HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
- CVE-2022-37081HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.
- CVE-2022-37082HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyncWithHost.
- CVE-2022-37083HIGHCVSS 7.8EG 7.82022-08-25
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisCfg.
- CVE-2022-37123HIGHCVSS 8.8EG 8.82022-08-31
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
- CVE-2022-37125CRITICALCVSS 9.8EG 9.82022-08-31
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
- CVE-2022-37129HIGHCVSS 8.8EG 8.82022-08-31
D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be exe…
- CVE-2022-37130CRITICALCVSS 9.8EG 9.82022-08-31
In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulti…
- CVE-2022-37149CRITICALCVSS 9.8EG 9.82022-08-30
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.
- CVE-2022-37425CRITICALCVSS 9.9EG 9.92022-10-28
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.
- CVE-2022-37704HIGHCVSS 6.7EG 7.82023-04-16
Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of p…
- CVE-2022-37718HIGHCVSS 8.8EG 8.82023-01-23
The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payloa…
- CVE-2022-37810CRITICALCVSS 9.8EG 9.82022-08-25
Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
- CVE-2022-37843CRITICALCVSS 9.8EG 9.82022-09-06
In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for execution without filtering, resulting in a command injection vulnerability.
- CVE-2022-37860CRITICALCVSS 9.8EG 9.82022-09-12
The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.
- CVE-2022-37878HIGHCVSS 7.2EG 7.22022-09-20
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2022-37879HIGHCVSS 7.2EG 7.22022-09-20
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2022-37881HIGHCVSS 7.2EG 7.22022-09-20
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2022-37883HIGHCVSS 7.2EG 7.22022-09-20
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2022-37893HIGHCVSS 7.8EG 7.82022-10-07
An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user o…
- CVE-2022-37897CRITICALCVSS 9.8EG 9.82022-12-12
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation …
- CVE-2022-37898HIGHCVSS 7.2EG 8.82022-12-12
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying opera…
- CVE-2022-37899HIGHCVSS 7.2EG 7.22022-12-12
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying opera…
- CVE-2022-37900HIGHCVSS 7.2EG 7.22022-12-12
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying opera…
- CVE-2022-37901HIGHCVSS 7.2EG 7.22022-12-12
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying opera…
- CVE-2022-37902HIGHCVSS 7.2EG 7.22022-12-12
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying opera…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →