CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 36 of 83
- CVE-2023-24184CRITICALCVSS 9.8EG 9.82023-02-21
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.
- CVE-2023-24229HIGHCVSS 7.8EG 7.82023-03-15
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects produ…
- CVE-2023-24236CRITICALCVSS 9.8EG 9.82023-02-16
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.
- CVE-2023-24238CRITICALCVSS 9.8EG 9.82023-02-16
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.
- CVE-2023-24276CRITICALCVSS 9.8EG 9.82023-02-06
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.
- CVE-2023-24330HIGHCVSS 8.8EG 8.82024-02-21
Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.
- CVE-2023-24331CRITICALCVSS 9.8EG 9.82024-02-21
Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.
- CVE-2023-24467HIGHCVSS 8.8EG 8.82024-11-22
Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.
- CVE-2023-24519HIGHCVSS 8.8EG 8.82023-07-06
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request …
- CVE-2023-24520HIGHCVSS 8.8EG 8.82023-07-06
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request …
- CVE-2023-24540CRITICALCVSS 9.8EG 9.82023-05-11
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not b…
- CVE-2023-24582HIGHCVSS 8.8EG 8.82023-07-06
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network requ…
- CVE-2023-24583HIGHCVSS 8.8EG 8.82023-07-06
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network requ…
- CVE-2023-24612CRITICALCVSS 9.8EG 9.82023-01-30
The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.
- CVE-2023-2491HIGHCVSS 7.8EG 7.82023-05-17
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 secur…
- CVE-2023-2520HIGHCVSS 8.8EG 8.82023-05-04
A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affects some unknown processing of the file cgi-bin/tools_ping.cgi?action=Command of the component Ping Handler. The manipula…
- CVE-2023-25643HIGHCVSS 8.4EG 8.42023-12-14
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands…
- CVE-2023-25649MEDIUMCVSS 6.8EG 6.82023-08-25
There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.
- CVE-2023-2573HIGHCVSS 8.8EG 8.82023-05-08
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.
- CVE-2023-2574HIGHCVSS 8.8EG 8.82023-05-08
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.
- CVE-2023-25805CRITICALCVSS 9.8EG 9.82023-02-20
versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1.0. This issue is patched in version 1.1.0.
- CVE-2023-25911CRITICALCVSS 9.9EG 9.92023-06-11
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.
- CVE-2023-26125MEDIUMCVSS 5.6EG 5.62023-05-04
Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning.…
- CVE-2023-26127HIGHCVSS 7.8EG 7.82023-05-27
All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the attacker needs…
- CVE-2023-26128HIGHCVSS 8.4EG 8.42023-05-27
All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the code snippet and po…
- CVE-2023-26129HIGHCVSS 8.4EG 8.42023-05-27
All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwm-ng.js file. **Note:** To execute the code snippet and potentially exploit the vulnerability, th…
- CVE-2023-26130HIGHCVSS 7.5EG 7.52023-05-30
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical erro…
- CVE-2023-26134CRITICALCVSS 9.8EG 9.82023-06-28
Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution AP…
- CVE-2023-26145HIGHCVSS 7.4EG 7.42023-09-28
This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to …
- CVE-2023-26155HIGHCVSS 7.3EG 7.32023-10-14
All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attacke…
- CVE-2023-26294HIGHCVSS 7.8EG 7.82023-06-12
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
- CVE-2023-26295CRITICALCVSS 9.8EG 9.82023-06-12
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
- CVE-2023-26296HIGHCVSS 8.8EG 8.82023-06-12
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
- CVE-2023-26297HIGHCVSS 8.8EG 8.82023-06-12
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
- CVE-2023-26298HIGHCVSS 8.8EG 8.82023-06-12
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
- CVE-2023-26310HIGHCVSS 7.4EG 7.42023-08-09
There is a command injection problem in the old version of the mobile phone backup app.
- CVE-2023-26315MEDIUMCVSS 6.5EG 6.52024-08-26
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the lack of input filtering, allowing an attacker to exploit it to obtain root access to the device.
- CVE-2023-26317CRITICALCVSS 7.0EG 9.82023-08-02
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hija…
- CVE-2023-26319MEDIUMCVSS 6.7EG 6.72023-10-11
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
- CVE-2023-26320HIGHCVSS 7.5EG 7.52023-10-11
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
- CVE-2023-26429LOWCVSS 3.5EG 3.52023-06-20
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are…
- CVE-2023-26430LOWCVSS 3.5EG 3.52023-08-02
Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEVE extension that are not allowed by App Suite or to inject rules which would break per-user filte…
- CVE-2023-2647MEDIUMCVSS 6.3EG 6.32023-05-11
A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroot/inc/utility_all.php of the component File Upload Handler. The manipulation leads to comm…
- CVE-2023-2649HIGHCVSS 7.2EG 7.22023-05-11
A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Port 7329. The manipulation of the argument v2 leads to command…
- CVE-2023-26493HIGHCVSS 8.1EG 8.12023-03-27
Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `web-interface-check.yml` was subject to command injection. The `web-interface-check.yml` wa…
- CVE-2023-26602CRITICALCVSS 9.8EG 9.82023-02-26
ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.
- CVE-2023-26800CRITICALCVSS 9.8EG 9.82023-03-26
Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function.
- CVE-2023-26801CRITICALCVSS 9.8EG 9.82023-03-26
LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cf…
- CVE-2023-2682MEDIUMCVSS 6.3EG 6.32023-05-12
A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/ping.cgi of the component Mini_HTTPD. The manipulation of the argument address with the in…
- CVE-2023-26822CRITICALCVSS 9.8EG 9.82023-04-01
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →