CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 33 of 83
- CVE-2022-46641CRITICALCVSS 9.9EG 9.92022-12-23
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.
- CVE-2022-46642CRITICALCVSS 9.9EG 9.92022-12-23
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.
- CVE-2022-47028MEDIUMCVSS 5.5EG 5.52023-05-30
An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function insert.
- CVE-2022-47210HIGHCVSS 7.8EG 7.82022-12-16
The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any auth…
- CVE-2022-47853CRITICALCVSS 9.8EG 9.82023-01-17
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a stable root shell through a specially constructed payload.
- CVE-2022-47909HIGHCVSS 6.8EG 7.82023-02-20
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's c…
- CVE-2022-48107CRITICALCVSS 9.8EG 9.82023-01-27
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
- CVE-2022-48108CRITICALCVSS 9.8EG 9.82023-01-27
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
- CVE-2022-48121CRITICALCVSS 9.8EG 9.82023-01-20
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/delStaticDhcpRules function.
- CVE-2022-48122CRITICALCVSS 9.8EG 9.82023-01-20
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the setting/delStaticDhcpRules function.
- CVE-2022-48123CRITICALCVSS 9.8EG 9.82023-01-20
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the setting/delStaticDhcpRules function.
- CVE-2022-48124CRITICALCVSS 9.8EG 9.82023-01-20
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the setting/setOpenVpnCertGenerationCfg function.
- CVE-2022-48125CRITICALCVSS 9.8EG 9.82023-01-20
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the setting/setOpenVpnCertGenerationCfg function.
- CVE-2022-48126CRITICALCVSS 9.8EG 9.82023-01-20
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenVpnCertGenerationCfg function.
- CVE-2022-48175CRITICALCVSS 9.8EG 9.82023-01-30
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.
- CVE-2022-48255CRITICALCVSS 9.8EG 9.82023-02-27
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution.
- CVE-2022-48259CRITICALCVSS 9.8EG 9.82023-02-27
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges.
- CVE-2022-48337CRITICALCVSS 9.8EG 9.82023-02-20
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a v…
- CVE-2022-48338CRITICALCVSS 7.3EG 9.82023-02-20
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Insi…
- CVE-2022-48339CRITICALCVSS 7.8EG 9.82023-02-20
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. …
- CVE-2022-4934HIGHCVSS 7.2EG 7.22023-04-04
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
- CVE-2023-0093HIGHCVSS 8.8EG 8.82023-03-06
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command …
- CVE-2023-0127HIGHCVSS 7.8EG 8.02023-02-11
A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to execute arbitrary commands as root.
- CVE-2023-0315CRITICALCVSS 8.8EG 9.02023-01-16
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
- CVE-2023-0351HIGHCVSS 8.8EG 8.82023-03-13
The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This could allow an attacker to upload files with executable command instructions.
- CVE-2023-0611HIGHCVSS 8.8EG 8.82023-02-01
A vulnerability, which was classified as critical, has been found in TRENDnet TEW-652BRP 3.04B01. This issue affects some unknown processing of the file get_set.ccp of the component Web Management Interface. The manipulation leads to comma…
- CVE-2023-0628HIGHCVSS 6.1EG 7.82023-03-13
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.
- CVE-2023-0636HIGHCVSS 7.2EG 7.22023-06-05
Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R20…
- CVE-2023-0638CRITICALCVSS 7.2EG 9.82023-02-02
A vulnerability has been found in TRENDnet TEW-811DRU 1.0.10.0 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated rem…
- CVE-2023-0640CRITICALCVSS 7.2EG 9.82023-02-02
A vulnerability was found in TRENDnet TEW-652BRP 3.04b01. It has been classified as critical. Affected is an unknown function of the file ping.ccp of the component Web Interface. The manipulation leads to command injection. It is possible …
- CVE-2023-0646HIGHCVSS 6.3EG 7.52023-02-02
A vulnerability classified as critical was found in dst-admin 1.5.0. Affected by this vulnerability is an unknown functionality of the file /home/cavesConsole. The manipulation of the argument command leads to command injection. The attack…
- CVE-2023-0647HIGHCVSS 6.3EG 7.52023-02-02
A vulnerability, which was classified as critical, has been found in dst-admin 1.5.0. Affected by this issue is some unknown functionality of the file /home/kickPlayer. The manipulation of the argument userId leads to command injection. Th…
- CVE-2023-0648HIGHCVSS 6.3EG 7.52023-02-02
A vulnerability, which was classified as critical, was found in dst-admin 1.5.0. This affects an unknown part of the file /home/masterConsole. The manipulation of the argument command leads to command injection. It is possible to initiate …
- CVE-2023-0649HIGHCVSS 6.3EG 7.52023-02-02
A vulnerability has been found in dst-admin 1.5.0 and classified as critical. This vulnerability affects unknown code of the file /home/sendBroadcast. The manipulation of the argument message leads to command injection. The attack can be i…
- CVE-2023-0776CRITICALCVSS 8.1EG 10.02023-02-11
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login executi…
- CVE-2023-0789HIGHCVSS 8.1EG 8.12023-02-12
Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
- CVE-2023-0830HIGHCVSS 6.3EG 8.82023-02-14
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has b…
- CVE-2023-0849CRITICALCVSS 4.7EG 9.82023-02-15
A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated remo…
- CVE-2023-0861HIGHCVSS 7.2EG 8.82023-02-16
NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. This issue affects …
- CVE-2023-0978MEDIUMCVSS 6.4EG 6.72023-03-13
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to …
- CVE-2023-1000MEDIUMCVSS 6.3EG 6.32024-04-27
A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plugins/notifications.py of the component Notification Handler. The manipulation leads to comm…
- CVE-2023-1097CRITICALCVSS 9.3EG 9.82023-03-01
Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The followin…
- CVE-2023-1141HIGHCVSS 8.8EG 8.82023-03-27
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution.
- CVE-2023-1162HIGHCVSS 7.2EG 8.82023-03-03
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is an unknown function of the file mainfunction.cgi of the component Web Management Interface. The…
- CVE-2023-1168HIGHCVSS 7.2EG 8.82023-03-22
An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the unde…
- CVE-2023-1270MEDIUMCVSS 5.4EG 5.42023-03-08
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
- CVE-2023-1277HIGHCVSS 7.8EG 7.82023-03-08
A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function InstallSnap of the component Update Handler. The manipulation leads to command injection. The a…
- CVE-2023-1389CRITICALCVSS 8.8EG 9.0⚠ KEV2023-03-15
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the countr…
- CVE-2023-1456CRITICALCVSS 7.2EG 9.82023-03-25
A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. This issue affects some unknown processing of the component NAT Configuration Handler. The manipulation leads to command injection. …
- CVE-2023-1457CRITICALCVSS 7.2EG 9.82023-03-25
A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. Affected is an unknown function of the component Static Routing Configuration Handler. The manipulation of the argument next-hop-interfac…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →