← Back
CWE-77

3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dcnetworks
1Dcme 320 Firmware
Jun 17, 2026
Nov 5, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.
-
-
Jun 17, 2026
Nov 5, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component
-
-
Jun 17, 2026
Nov 5, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a pr...Show more
An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying host operating system.Show less
-
-
Jun 17, 2026
Nov 5, 2024
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP p...Show more
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.Show less
-
-
Jun 17, 2026
Nov 5, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP p...Show more
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.Show less
1Hp
8Poly Studio G62 Firmware
Poly Studio G7500 FirmwarePoly Studio X30 Firmware+5 more
Jun 17, 2026
Nov 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and ca...Show more
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.Show less
1Netgear
4R6400v2 Firmware
R7000p FirmwareR8500 Firmware+1 more
Jun 17, 2026
Nov 5, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulner...Show more
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.Show less
1Bg Tek
1Coslat
Jun 17, 2026
Nov 4, 2024
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Comma...Show more
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection, Privilege Escalation. This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that the product is not supported.Show less
1Tenda
1Ac6 Firmware
Jun 17, 2026
Nov 2, 2024
5.3 MEDIUM· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipu...Show more
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument mac leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 31, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 31, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 31, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.
-
-
Jun 17, 2026
Oct 30, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code...Show more
KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR code. By that, the attacker can execute arbitrary code on the camera.Show less
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.