CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 37 of 83
- CVE-2023-26848CRITICALCVSS 9.8EG 9.82023-04-07
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.
- CVE-2023-26866CRITICALCVSS 9.8EG 9.82023-04-04
GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands are executed using pre-login execution and executed with r…
- CVE-2023-26978CRITICALCVSS 9.8EG 9.82023-04-07
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.
- CVE-2023-27078CRITICALCVSS 9.8EG 9.82023-03-23
A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to the tftp endpoint.
- CVE-2023-27079HIGHCVSS 7.5EG 7.52023-03-23
Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package
- CVE-2023-27135CRITICALCVSS 9.8EG 9.82023-03-23
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.
- CVE-2023-27224CRITICALCVSS 9.8EG 9.82023-03-22
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.
- CVE-2023-27229CRITICALCVSS 9.8EG 9.82023-03-28
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.
- CVE-2023-27231CRITICALCVSS 9.8EG 9.82023-03-28
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg.
- CVE-2023-27232CRITICALCVSS 9.8EG 9.82023-03-28
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg.
- CVE-2023-27240CRITICALCVSS 9.8EG 9.82023-03-15
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.
- CVE-2023-27407CRITICALCVSS 9.9EG 9.92023-05-09
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated…
- CVE-2023-27581HIGHCVSS 8.8EG 8.82023-03-13
github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workflow. Starting in version 4.0.0` and prior to version 4.4.1, this action uses the `github.head_ref` parameter in an insec…
- CVE-2023-27796HIGHCVSS 8.8EG 8.82023-03-26
RG-EW1200G PRO Wireless Routers EW_3.0(1)B11P204, RG-EW1800GX PRO Wireless Routers EW_3.0(1)B11P204, and RG-EW3200GX PRO Wireless Routers EW_3.0(1)B11P204 were discovered to contain multiple command injection vulnerabilities via the data.i…
- CVE-2023-27836CRITICALCVSS 9.8EG 9.82023-06-13
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.
- CVE-2023-27837CRITICALCVSS 9.8EG 9.82023-06-13
TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 40A774.
- CVE-2023-27848CRITICALCVSS 9.8EG 9.82023-04-24
broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- CVE-2023-27849CRITICALCVSS 9.8EG 9.82023-04-24
rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- CVE-2023-28012MEDIUMCVSS 5.4EG 6.62023-07-27
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
- CVE-2023-28110MEDIUMCVSS 5.7EG 5.72023-03-16
Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to …
- CVE-2023-28130HIGHCVSS 7.2EG 7.22023-07-26
Local user may lead to privilege escalation using Gaia Portal hostnames page.
- CVE-2023-28365CRITICALCVSS 9.1EG 9.12023-07-01
A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.
- CVE-2023-28425HIGHCVSS 5.5EG 7.12023-03-20
Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The pro…
- CVE-2023-28430HIGHCVSS 7.3EG 7.32023-03-27
OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions Git…
- CVE-2023-28460HIGHCVSS 7.2EG 7.22023-03-15
A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This i…
- CVE-2023-28489CRITICALCVSS 9.8EG 9.82023-04-11
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the param…
- CVE-2023-28677CRITICALCVSS 9.8EG 9.82023-04-02
Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able t…
- CVE-2023-2868CRITICALCVSS 9.4EG 9.4⚠ KEV2023-05-24
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the …
- CVE-2023-28704HIGHCVSS 8.8EG 8.82023-06-02
Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Bluetooth network with normal user privileges can exploit this vulnerability to perform command …
- CVE-2023-28712CRITICALCVSS 8.2EG 9.82023-03-28
Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions.
- CVE-2023-28832HIGHCVSS 7.2EG 7.22023-05-09
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The web based management of affected devices does not properly validate user i…
- CVE-2023-28854HIGHCVSS 8.0EG 8.02023-04-03
nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A patch was made available at commit e5409aa2d441789cbb35f6b119bef97ecc3986aa on 2023-03-30. Users should update index.php …
- CVE-2023-28935HIGHCVSS 8.8EG 8.82023-03-30
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) …
- CVE-2023-29084CRITICALCVSS 7.2EG 9.02023-04-13
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
- CVE-2023-2910HIGHCVSS 8.8EG 8.82023-08-17
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified …
- CVE-2023-29473CRITICALCVSS 9.8EG 9.82023-04-06
webservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, a…
- CVE-2023-29474CRITICALCVSS 9.8EG 9.82023-04-06
inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, ak…
- CVE-2023-29475CRITICALCVSS 9.8EG 9.82023-04-06
inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, ak…
- CVE-2023-29566CRITICALCVSS 9.8EG 9.82023-04-24
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- CVE-2023-29798CRITICALCVSS 9.8EG 9.82023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.
- CVE-2023-29799CRITICALCVSS 9.8EG 9.82023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
- CVE-2023-29800CRITICALCVSS 9.8EG 9.82023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
- CVE-2023-29801CRITICALCVSS 9.8EG 9.82023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.
- CVE-2023-29802CRITICALCVSS 9.8EG 9.82023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
- CVE-2023-29803CRITICALCVSS 9.8EG 9.82023-04-14
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.
- CVE-2023-29855HIGHCVSS 7.2EG 7.22023-04-18
WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php.
- CVE-2023-30135CRITICALCVSS 9.8EG 9.82023-05-05
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.
- CVE-2023-30258CRITICALCVSS 9.8EG 9.82023-06-23
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
- CVE-2023-30260HIGHCVSS 8.8EG 8.82023-06-23
Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.
- CVE-2023-30353CRITICALCVSS 9.8EG 9.82023-05-10
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →