CWE-77
3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,620)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfilterset, hassiscfgperrthreshold, supports...Show more |
An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operatin...Show more |
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/networking/get_wgkey.php. |
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php...Show more |
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name. |
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
|
HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.
|
Local user may lead to privilege escalation using Gaia Portal hostnames page. |
WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp. |
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778. |
2Codecentric Thymeleaf2Spring Boot Admin ThymeleafJun 17, 2026 Jul 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injectio...Show more |
1Elecom 2Wrc 1167gebk S Firmware Wrc 1167ghbk S FirmwareJun 17, 2026 Jul 13, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to...Show more |
1Elecom 1Wrc 1167ghbk3 A Firmware Jun 17, 2026 Jul 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web mana...Show more |
1Elecom 2Wrc 1167febk A Firmware Wrc 1167ghbk3 A FirmwareJun 17, 2026 Jul 13, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management pag...Show more |
1Siemens 11Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V...Show more |
1Siemens 11Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V...Show more |
1Siemens 11Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V...Show more |
1Siemens 11Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V...Show more |
1Siemens 11Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V...Show more |
1Siemens 11Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V...Show more |