CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 31 of 83
- CVE-2022-37912HIGHCVSS 7.2EG 8.82022-12-12
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying opera…
- CVE-2022-38156HIGHCVSS 7.2EG 7.22023-06-12
A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admin user, an attacker can send a crafted password in order to execute Linux commands as the …
- CVE-2022-38308CRITICALCVSS 9.8EG 9.82022-09-14
TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.
- CVE-2022-38511HIGHCVSS 7.8EG 7.82022-08-29
TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.
- CVE-2022-38531HIGHCVSS 8.8EG 8.82022-09-08
FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.
- CVE-2022-38534HIGHCVSS 7.2EG 7.22022-09-15
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function.
- CVE-2022-38535HIGHCVSS 7.2EG 7.22022-09-15
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.
- CVE-2022-38826CRITICALCVSS 9.8EG 9.82022-09-16
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.
- CVE-2022-38828CRITICALCVSS 9.8EG 9.82022-09-16
TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi
- CVE-2022-39057HIGHCVSS 7.2EG 7.22022-10-18
RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system command and disrupt …
- CVE-2022-39073CRITICALCVSS 9.8EG 9.82023-01-06
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.
- CVE-2022-39081MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39082MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39083MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39084MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39085MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39086MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39087MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39088MEDIUMCVSS 6.7EG 6.72023-01-04
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.
- CVE-2022-39243HIGHCVSS 8.4EG 8.42022-09-26
NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in th…
- CVE-2022-39265HIGHCVSS 7.2EG 7.22022-10-06
MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access t…
- CVE-2022-39986CRITICALCVSS 9.8EG 9.82023-08-01
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
- CVE-2022-39987HIGHCVSS 8.8EG 8.82023-08-01
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/networking/get_wgkey.php.
- CVE-2022-4002HIGHCVSS 7.2EG 7.22024-07-31
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
- CVE-2022-40021CRITICALCVSS 9.8EG 9.82023-02-17
QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.
- CVE-2022-40022CRITICALCVSS 9.8EG 9.82023-02-13
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
- CVE-2022-4009HIGHCVSS 8.8EG 8.82023-03-16
In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation
- CVE-2022-40100CRITICALCVSS 9.8EG 9.82022-09-23
Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.
- CVE-2022-40282HIGHCVSS 8.8EG 8.82022-11-25
The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function …
- CVE-2022-40469HIGHCVSS 8.8EG 8.82022-10-12
iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.
- CVE-2022-40475CRITICALCVSS 9.8EG 9.82022-09-29
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.
- CVE-2022-40619HIGHCVSS 7.7EG 7.72026-01-28
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through t…
- CVE-2022-40746HIGHCVSS 7.2EG 7.22022-11-21
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file…
- CVE-2022-40752CRITICALCVSS 9.8EG 9.82022-11-16
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.
- CVE-2022-40765CRITICALCVSS 6.8EG 9.0⚠ KEV2022-11-22
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of…
- CVE-2022-40770HIGHCVSS 7.2EG 8.92022-11-23
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
- CVE-2022-40785HIGHCVSS 8.8EG 8.82022-09-26
Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially craft…
- CVE-2022-40881CRITICALCVSS 9.8EG 9.82022-11-17
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
- CVE-2022-41518CRITICALCVSS 9.8EG 9.82022-10-06
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.
- CVE-2022-41617HIGHCVSS 7.2EG 7.22022-10-19
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iC…
- CVE-2022-41800HIGHCVSS 8.7EG 8.92022-12-07
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can …
- CVE-2022-41870CRITICALCVSS 7.2EG 9.82022-09-30
AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.
- CVE-2022-41955HIGHCVSS 8.8EG 8.82023-01-14
Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignments to their students over the Web. A remote code execution v…
- CVE-2022-42156HIGHCVSS 8.8EG 8.82022-10-13
D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings.
- CVE-2022-42160HIGHCVSS 8.8EG 8.82022-10-13
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNTPServerSettings.
- CVE-2022-42161HIGHCVSS 8.8EG 8.82022-10-13
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTriggerWPS.
- CVE-2022-42187MEDIUMCVSS 6.1EG 6.12022-11-17
Hustoj 22.09.22 has a XSS Vulnerability in /admin/problem_judge.php.
- CVE-2022-42221HIGHCVSS 8.8EG 8.82022-10-17
Netgear R6220 v1.1.0.114_1.0.1 suffers from Incorrect Access Control, resulting in a command injection vulnerability.
- CVE-2022-42897CRITICALCVSS 9.8EG 9.82022-10-13
Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.
- CVE-2022-42904HIGHCVSS 7.2EG 7.22022-11-18
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →