← Back
CWE-77

3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Flir
1Flir Ax8 Firmware
Jun 17, 2026
Jan 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that with the introduction of firmware version...Show more
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.Show less
1Tenda
1Ax1803 Firmware
Jun 17, 2026
Jan 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
1Cassianetworks
2Xc1000 Firmware
Xc2000 Firmware
Jun 17, 2026
Jan 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device...Show more
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.Show less
1Microsoft
1Azure Storage Mover
Jun 17, 2026
Jan 9, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Azure Storage Mover Remote Code Execution Vulnerability
1Trendnet
1Tv Ip1314pi Firmware
Jun 17, 2026
Jan 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.
1Demon1a
1Discord Recon
Jun 17, 2026
Jan 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute sh...Show more
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8. Show less
1Totolink
1Lr1200gb Firmware
Jun 17, 2026
Jan 8, 2024
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument F...Show more
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249857 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Qnap
1Qumagie
Jun 17, 2026
Jan 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in th...Show more
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later Show less
1Tenda
1Ax3 Firmware
Jun 17, 2026
Jan 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
1Tj Actions
1Verify Changed Files
Jun 17, 2026
Dec 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak se...Show more
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow returns the list of files changed within a workflow execution. This could potentially allow filenames that contain special characters such as `;` which can be used by an attacker to take over the [GitHub Runner](https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners) if the output value is used in a raw fashion (thus being directly replaced before execution) inside a `run` block. By running custom commands, an attacker may be able to steal secrets such as `GITHUB_TOKEN` if triggered on other events than `pull_request`. This has been patched in versions [17](https://github.com/tj-actions/verify-changed-files/releases/tag/v17) and [17.0.0](https://github.com/tj-actions/verify-changed-files/releases/tag/v17.0.0) by enabling `safe_output` by default and returning filename paths escaping special characters for bash environments.Show less
1Gl Inet
12Gl A1300 Firmware
Gl Ar300m FirmwareGl Ar750 Firmware+9 more
Jun 17, 2026
Dec 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3....Show more
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local attackers to execute arbitrary code via the get_system_log and get_crash_log functions of the logread module, as well as the upgrade_online function of the upgrade module.Show less
1Tj Actions
1Changed Files
Jun 17, 2026
Dec 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execu...Show more
tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. This issue may lead to arbitrary command execution in the GitHub Runner. This vulnerability has been addressed in version 41.0.0. Users are advised to upgrade.Show less
1Peplink
1Balance Two Firmware
Jun 17, 2026
Dec 25, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
1Totolink
1Ex1800t Firmware
Jun 17, 2026
Dec 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.
1Totolink
1Ex1800t Firmware
Jun 17, 2026
Dec 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi
1Totolink
1Ex1800t Firmware
Jun 17, 2026
Dec 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.
1Arraynetworks
1Arrayos Ag
Jun 17, 2026
Dec 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected.
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
1Tenda
1I29 Firmware
Jul 9, 2026
Dec 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
1Lfprojects
1Mlflow
Jun 17, 2026
Dec 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.