CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 40 of 83
- CVE-2023-3739MEDIUMCVSS 6.3EG 6.32023-08-01
Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)
- CVE-2023-37469HIGHCVSS 8.8EG 8.82023-08-24
CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a controlled SMB server, they are able to execute arbitrary commands. Version 0.4.4 contains a…
- CVE-2023-37566HIGHCVSS 8.0EG 8.02023-07-13
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management page. Affected product…
- CVE-2023-37567CRITICALCVSS 9.8EG 9.82023-07-13
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affect…
- CVE-2023-37568HIGHCVSS 8.0EG 8.02023-07-13
ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management…
- CVE-2023-37679CRITICALCVSS 9.8EG 9.82023-08-03
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
- CVE-2023-37794CRITICALCVSS 9.8EG 9.82023-07-14
WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.
- CVE-2023-38027CRITICALCVSS 9.8EG 9.82023-08-28
SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system comma…
- CVE-2023-38034CRITICALCVSS 9.8EG 9.82023-08-10
A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53…
- CVE-2023-38120HIGHCVSS 8.8EG 8.82024-05-03
Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adtran SR400ac routers. Although authentication is required to exp…
- CVE-2023-38193HIGHCVSS 8.8EG 8.82023-10-21
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
- CVE-2023-38286HIGHCVSS 7.5EG 7.52023-07-14
Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code executi…
- CVE-2023-38336CRITICALCVSS 9.8EG 9.82023-07-14
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.
- CVE-2023-38690MEDIUMCVSS 5.8EG 5.82023-08-04
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, wh…
- CVE-2023-38829HIGHCVSS 8.8EG 8.82023-09-11
An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.
- CVE-2023-38861CRITICALCVSS 9.8EG 9.82023-08-15
An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.
- CVE-2023-38862CRITICALCVSS 9.8EG 9.82023-08-15
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt.
- CVE-2023-38863CRITICALCVSS 9.8EG 9.82023-08-15
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt.
- CVE-2023-38864CRITICALCVSS 9.8EG 9.82023-08-15
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.
- CVE-2023-38865CRITICALCVSS 9.8EG 9.82023-08-15
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.
- CVE-2023-38866CRITICALCVSS 9.8EG 9.82023-08-15
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name.
- CVE-2023-38902HIGHCVSS 8.8EG 8.82023-08-17
A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless …
- CVE-2023-38921HIGHCVSS 8.8EG 8.82023-08-07
Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via the firmwareRestore and firmwareServerip parameters.
- CVE-2023-38928CRITICALCVSS 9.8EG 9.82023-08-07
Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.
- CVE-2023-38941CRITICALCVSS 9.8EG 9.82023-08-04
django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post.
- CVE-2023-38942CRITICALCVSS 9.8EG 9.82023-08-03
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.
- CVE-2023-39001CRITICALCVSS 9.8EG 9.82023-08-09
A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.
- CVE-2023-39008CRITICALCVSS 9.8EG 9.82023-08-09
A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.
- CVE-2023-39293CRITICALCVSS 9.8EG 9.82023-08-14
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
- CVE-2023-39362HIGHCVSS 7.2EG 8.92023-09-05
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command inje…
- CVE-2023-39471HIGHCVSS 8.8EG 8.82024-05-03
TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Authentication is not r…
- CVE-2023-39509HIGHCVSS 7.2EG 7.22023-12-18
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands on the OS of the camera.
- CVE-2023-39523MEDIUMCVSS 6.8EG 6.82023-08-07
ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a possible command injection vulnerability in the docker fetch process as it allows to append m…
- CVE-2023-39617CRITICALCVSS 9.8EG 9.82023-08-21
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
- CVE-2023-39618CRITICALCVSS 9.8EG 9.82023-08-21
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.
- CVE-2023-39637CRITICALCVSS 9.8EG 9.82023-09-12
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
- CVE-2023-39638CRITICALCVSS 9.8EG 9.82023-09-14
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.
- CVE-2023-39780CRITICALCVSS 8.8EG 9.0⚠ KEV2023-09-11
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the simil…
- CVE-2023-39809CRITICALCVSS 9.8EG 9.82023-08-21
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.
- CVE-2023-39834CRITICALCVSS 9.8EG 9.82023-08-24
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
- CVE-2023-40146MEDIUMCVSS 6.8EG 6.82024-04-17
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can a…
- CVE-2023-40263HIGHCVSS 8.8EG 8.82024-02-08
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.
- CVE-2023-40293MEDIUMCVSS 6.8EG 6.82023-08-14
Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.
- CVE-2023-40301CRITICALCVSS 9.8EG 9.82023-12-07
NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.
- CVE-2023-40396HIGHCVSS 7.8EG 7.82024-07-29
The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2023-40598HIGHCVSS 8.5EG 8.52023-08-30
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation…
- CVE-2023-40796HIGHCVSS 7.8EG 7.82023-08-25
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
- CVE-2023-41011CRITICALCVSS 9.8EG 9.82023-09-14
Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component.
- CVE-2023-41029HIGHCVSS 8.8EG 8.82023-09-22
Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute commands as root via specially crafte…
- CVE-2023-41031HIGHCVSS 8.8EG 8.82023-09-22
Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute commands via specially crafted requests to the vulnerable endpoint.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →