CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,331 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 73 of 87
- CVE-2026-2063HIGHCVSS 7.2EG 7.22026-02-06
A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the component Web Management Interface. The manipulation of the argument ac_server results in os co…
- CVE-2026-20671LOWCVSS 3.1EG 3.12026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attack…
- CVE-2026-20675MEDIUMCVSS 5.5EG 5.52026-02-11
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Proces…
- CVE-2026-20761HIGHCVSS 8.1EG 8.12026-02-20
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command executi…
- CVE-2026-2080HIGHCVSS 7.2EG 7.22026-02-07
A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injection. Remote exploitation of the attack is…
- CVE-2026-2081HIGHCVSS 7.2EG 7.22026-02-07
A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The attack is possible to be…
- CVE-2026-2082HIGHCVSS 7.2EG 7.22026-02-07
A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command injection. The attack may be performed from …
- CVE-2026-2084HIGHCVSS 7.2EG 7.22026-02-07
A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os command injection. It is possible to launch …
- CVE-2026-20841HIGHCVSS 7.8EG 8.82026-02-10
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.
- CVE-2026-2085HIGHCVSS 7.2EG 7.22026-02-07
A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to c…
- CVE-2026-2118HIGHCVSS 7.2EG 7.22026-02-08
A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation of the argument Isp_Name can lead to co…
- CVE-2026-2120HIGHCVSS 7.2EG 7.22026-02-08
A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_server_settings of the component Configuration Parameter Handler. The manipulation of the argument terminal_addr/server_ip/s…
- CVE-2026-21256HIGHCVSS 8.8EG 8.82026-02-10
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
- CVE-2026-21257HIGHCVSS 8.0EG 8.02026-02-10
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
- CVE-2026-2129HIGHCVSS 7.2EG 7.22026-02-08
A vulnerability was found in D-Link DIR-823X 250416. Affected by this issue is some unknown functionality of the file /goform/set_ac_status. Performing a manipulation of the argument ac_ipaddr/ac_ipstatus/ap_randtime results in os command …
- CVE-2026-2130CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/index.ts of the component search_username. Executing a manipulation of the argument Username can lead to command injectio…
- CVE-2026-2131HIGHCVSS 8.8EG 8.82026-02-08
A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument text leads to os command injection. Remote exploitation of the attack is possibl…
- CVE-2026-2135HIGHCVSS 8.8EG 8.82026-02-08
A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_43F020 of the file /goform/formPdbUpConfig. Performing a manipulation of the argument policyNames results in command injection. It is poss…
- CVE-2026-2142HIGHCVSS 7.2EG 7.22026-02-08
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420688 of the file /goform/set_qos. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The e…
- CVE-2026-2143HIGHCVSS 7.2EG 7.22026-02-08
A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the component DDNS Service. The manipulation of the argument ddnsType/ddnsDomainName/ddnsUserN…
- CVE-2026-2151HIGHCVSS 7.2EG 7.22026-02-08
A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr leads to os command injection. The attack ca…
- CVE-2026-21516HIGHCVSS 7.8EG 8.82026-02-10
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
- CVE-2026-21518HIGHCVSS 8.8EG 8.82026-02-10
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-2152HIGHCVSS 7.2EG 7.22026-02-08
A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/ submask/ gw results in…
- CVE-2026-21520HIGHCVSS 7.5EG 7.52026-01-22
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
- CVE-2026-21522MEDIUMCVSS 6.7EG 6.72026-02-10
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
- CVE-2026-2155HIGHCVSS 7.2EG 7.22026-02-08
A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument dmz_host/dmz_enable results…
- CVE-2026-2157HIGHCVSS 7.2EG 7.22026-02-08
A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table. Such manipulation of the argument interface/destip/netmask/gateway/metric leads to os co…
- CVE-2026-2163HIGHCVSS 7.2EG 7.22026-02-08
A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The att…
- CVE-2026-21638HIGHCVSS 8.8EG 8.82026-01-08
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products: UBB-XG (Version 1.2.2 an…
- CVE-2026-21639MEDIUMCVSS 5.4EG 5.42026-01-08
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.
- CVE-2026-2167HIGHCVSS 8.8EG 8.82026-02-08
A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Ipaddr results in os command injection. The attack ma…
- CVE-2026-2168HIGHCVSS 8.8EG 8.82026-02-08
A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. It is possible to initiate the attack…
- CVE-2026-2169HIGHCVSS 8.8EG 8.82026-02-08
A vulnerability has been found in D-Link DWR-M921 1.1.50. This impacts an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command injection. It is possible to launch the a…
- CVE-2026-21709MEDIUMCVSS 6.7EG 6.72026-04-17
A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.
- CVE-2026-2175HIGHCVSS 7.2EG 7.22026-02-08
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manipulation of the argument upnp_enable causes os command injection. Remote exploitation of th…
- CVE-2026-2178HIGHCVSS 8.8EG 8.82026-02-08
A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the arg…
- CVE-2026-2182HIGHCVSS 7.2EG 7.22026-02-08
A weakness has been identified in UTT 进取 521G 3.1.1-190816. Affected by this issue is the function doSystem of the file /goform/setSysAdm. Executing a manipulation of the argument passwd1 can lead to command injection. The attack may b…
- CVE-2026-2184CRITICALCVSS 9.8EG 9.82026-02-08
A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This vulnerability affects unknown code of the file /restructured/csv.php. The manipulation of the argument phot…
- CVE-2026-2188HIGHCVSS 7.2EG 7.22026-02-08
A vulnerability was determined in UTT 进取 521G 3.1.1-190816. The impacted element is the function sub_446B18 of the file /goform/formPdbUpConfig. Executing a manipulation of the argument policyNames can lead to os command injection. It …
- CVE-2026-2193HIGHCVSS 8.8EG 8.82026-02-08
A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack i…
- CVE-2026-2194HIGHCVSS 8.8EG 8.82026-02-09
A flaw has been found in D-Link DI-7100G C1 24.04.18D1. This affects the function start_proxy_client_email. Executing a manipulation can lead to command injection. The attack can be executed remotely. The exploit has been published and may…
- CVE-2026-22095CRITICALCVSS 9.3EG 9.32026-07-13
The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
- CVE-2026-2210HIGHCVSS 7.2EG 7.22026-02-09
A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The exploit has been di…
- CVE-2026-22103CRITICALCVSS 9.3EG 9.32026-07-13
The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
- CVE-2026-2218HIGHCVSS 8.8EG 8.82026-02-09
A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID causes command injection. Remote exploitation…
- CVE-2026-2227HIGHCVSS 7.2EG 7.22026-02-09
A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely.…
- CVE-2026-22284HIGHCVSS 7.2EG 7.22026-02-17
Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exp…
- CVE-2026-22317HIGHCVSS 7.2EG 7.22026-03-18
A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacker to send crafted HTTP POST requests that result in arbitrary command execution on the underlying Linux OS with root …
- CVE-2026-2256MEDIUMCVSS 6.5EG 6.52026-03-02
A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →