CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 38 of 83
- CVE-2023-30400CRITICALCVSS 9.8EG 9.82023-06-07
An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within the MCU's operating system allows attackers to perform arbitrary command execution via a cr…
- CVE-2023-30535HIGHCVSS 7.3EG 7.32023-04-14
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to a command injection vulnerability. An attacker could set up…
- CVE-2023-30623HIGHCVSS 8.8EG 8.82023-04-24
`embano1/wip` is a GitHub Action written in Bash. Prior to version 2, the `embano1/wip` action uses the `github.event.pull_request.title` parameter in an insecure way. The title parameter is used in a run statement - resulting in a comman…
- CVE-2023-30638HIGHCVSS 7.2EG 7.22023-04-14
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.
- CVE-2023-31208HIGHCVSS 8.3EG 8.32023-05-17
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
- CVE-2023-31429MEDIUMCVSS 5.5EG 5.52023-08-01
Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfilterset, hassiscfgperrthreshold, supportshowcfgd…
- CVE-2023-31446CRITICALCVSS 9.8EG 9.82024-01-10
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.
- CVE-2023-31460HIGHCVSS 7.2EG 7.22023-05-24
A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient rest…
- CVE-2023-31473MEDIUMCVSS 4.9EG 4.92023-05-11
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through …
- CVE-2023-31476HIGHCVSS 7.5EG 7.52023-05-09
An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characte…
- CVE-2023-31528HIGHCVSS 8.8EG 8.82023-05-11
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter.
- CVE-2023-31529HIGHCVSS 8.8EG 8.82023-05-11
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.
- CVE-2023-31530HIGHCVSS 8.8EG 8.82023-05-11
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.
- CVE-2023-31531HIGHCVSS 8.8EG 8.82023-05-11
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.
- CVE-2023-31569CRITICALCVSS 9.8EG 9.82023-06-06
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.
- CVE-2023-31700HIGHCVSS 8.8EG 8.82023-05-17
TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceAdd.
- CVE-2023-31701HIGHCVSS 8.8EG 8.82023-05-17
TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceRemove.
- CVE-2023-31729CRITICALCVSS 9.8EG 9.82023-05-18
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.
- CVE-2023-31740HIGHCVSS 7.2EG 7.22023-05-23
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb, WL_atten_radio, and…
- CVE-2023-31741HIGHCVSS 7.2EG 7.22023-05-23
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_att…
- CVE-2023-31742HIGHCVSS 7.2EG 7.22023-05-22
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten…
- CVE-2023-31746CRITICALCVSS 9.8EG 9.82023-06-14
There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.
- CVE-2023-31856CRITICALCVSS 9.8EG 9.82023-05-16
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
- CVE-2023-31983CRITICALCVSS 9.8EG 9.82023-05-12
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.
- CVE-2023-31985CRITICALCVSS 9.8EG 9.82023-05-12
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations.
- CVE-2023-31986CRITICALCVSS 9.8EG 9.82023-05-15
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.
- CVE-2023-31996HIGHCVSS 8.8EG 8.82023-05-23
Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test function.
- CVE-2023-32007CRITICALCVSS 8.8EG 9.02023-05-02
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify th…
- CVE-2023-3206MEDIUMCVSS 5.3EG 5.32023-06-12
A vulnerability classified as problematic was found in Chengdu VEC40G 3.0. Affected by this vulnerability is an unknown functionality of the file /send_order.cgi?parameter=restart. The manipulation of the argument restart with the input re…
- CVE-2023-32073HIGHCVSS 8.8EG 8.82023-05-12
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to t…
- CVE-2023-32632HIGHCVSS 8.8EG 8.82023-10-11
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger th…
- CVE-2023-32700HIGHCVSS 7.8EG 7.82023-05-20
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 20…
- CVE-2023-32781CRITICALCVSS 7.2EG 9.82023-08-09
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get exec…
- CVE-2023-32782CRITICALCVSS 7.2EG 9.82023-08-09
A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed …
- CVE-2023-33136HIGHCVSS 8.8EG 8.82023-09-12
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-33235HIGHCVSS 7.2EG 7.22023-05-22
MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out…
- CVE-2023-33238HIGHCVSS 7.2EG 7.22023-08-17
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from inadequate input validation in the certificate manag…
- CVE-2023-33239HIGHCVSS 8.8EG 8.82023-08-17
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation …
- CVE-2023-33294CRITICALCVSS 9.8EG 9.82023-05-22
An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST requests on port 2929. The server accepts arbitrary Bash commands and executes them as root. Bec…
- CVE-2023-33298HIGHCVSS 7.8EG 7.82023-06-30
com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell metacharacters in usingCAPath.
- CVE-2023-33300MEDIUMCVSS 5.3EG 5.32025-03-14
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-s…
- CVE-2023-33486CRITICALCVSS 9.8EG 9.82023-05-31
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.
- CVE-2023-33487CRITICALCVSS 9.8EG 9.82023-05-31
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.
- CVE-2023-33530HIGHCVSS 8.8EG 8.82023-06-06
There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
- CVE-2023-33532CRITICALCVSS 9.8EG 9.82023-06-06
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privile…
- CVE-2023-33533HIGHCVSS 8.8EG 8.82023-06-06
Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management pri…
- CVE-2023-33538CRITICALCVSS 8.8EG 9.0⚠ KEV2023-06-07
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .
- CVE-2023-33556CRITICALCVSS 9.8EG 9.82023-06-07
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
- CVE-2023-33625CRITICALCVSS 9.8EG 9.82023-06-12
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.
- CVE-2023-33722HIGHCVSS 8.8EG 8.82023-05-31
EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →