← Back
CWE-77

3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Oct 17, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
1Netgear
1R7000 Firmware
Jun 17, 2026
Oct 14, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
1Netgear
3Ex3700 Firmware
Ex6100 FirmwareEx6120 Firmware
Jun 17, 2026
Oct 14, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.
1Netgear
1Ex6120 Firmware
Jun 17, 2026
Oct 14, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Oct 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.
1Netgear
1Ex3700 Firmware
Jun 17, 2026
Oct 11, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set to 1 and ap_24g_manual_sec...Show more
Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set to 1 and ap_24g_manual_sec set to NotNone.Show less
1Netgear
1Xr1000 Firmware
Jun 17, 2026
Oct 11, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
-
-
Jun 17, 2026
Oct 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead...Show more
A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.Show less
1Juniper
1Junos Space
Jun 17, 2026
Oct 11, 2024
6.9 MEDIUM· v4
7.3 HIGH· v3
N/A· v2
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, le...Show more
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the web application, gaining complete control of the device. A specific script in the Junos Space web application allows attacker-controlled input from a GET request without sufficient input sanitization. A specially crafted request can exploit this vulnerability to execute arbitrary shell commands on the Junos Space Appliance. This issue affects Junos Space 24.1R1. Previous versions of Junos Space are unaffected by this vulnerability.Show less
1Tenda
1Ac1206 Firmware
Jun 17, 2026
Oct 10, 2024
5.3 MEDIUM· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injec...Show more
A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Jun 17, 2026
Oct 9, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
1Progress
1Telerik Reporting
Jun 17, 2026
Oct 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
1Google
1Android
Jun 17, 2026
Oct 9, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
1Google
1Android
Jun 17, 2026
Oct 9, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
1Google
1Android
Jun 17, 2026
Oct 9, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
-
-
Jun 17, 2026
Oct 9, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended beha...Show more
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.Show less
1Microsoft
1Visual Studio Code
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Visual Studio Code for Linux Remote Code Execution Vulnerability
1Microsoft
2Azure Command Line Interface
Azure Service Connector
Jun 17, 2026
Oct 8, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
1Microsoft
1Deepspeed
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
DeepSpeed Remote Code Execution Vulnerability
1Ivanti
1Endpoint Manager Cloud Services Appliance
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.