CWE-77
3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,618)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. |
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. |
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function. |
1Atos 3Unify Openscape Bcf Unify Openscape BranchUnify Openscape Session Border ControllerJun 17, 2026 Apr 14, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Apr 13, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. |
1Cisco 6Rv016 Firmware Rv042 FirmwareRv042g Firmware+3 moreJun 17, 2026 Apr 13, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on a...Show more |
1Siemens 2Cp 8031 Firmware Cp 8050 FirmwareJun 17, 2026 Apr 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 44...Show more |
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg. |
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules. |
1Atos 2Unify Openscape 4000 Unify Openscape 4000 ManagerJun 17, 2026 Apr 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve admini...Show more |
1Atos 2Unify Openscape 4000 Unify Openscape 4000 ManagerJun 17, 2026 Apr 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve admini...Show more |
1Atos 2Unify Openscape 4000 Unify Openscape 4000 ManagerJun 17, 2026 Apr 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 webservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve admin...Show more |
An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected com...Show more |
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate priv...Show more |
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to...Show more |
1Cisco 3Evolved Programmable Network Manager Identity Services EnginePrime InfrastructureJun 17, 2026 Apr 5, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to...Show more |
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate priv...Show more |
1Cisco 6Rv016 Firmware Rv042 FirmwareRv042g Firmware+3 moreJun 17, 2026 Apr 5, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affect...Show more |
Command Injection in GitHub repository microweber/microweber prior to 1.3.3. |
1Greenpacket 2Ot 235 Firmware Wr 1200 FirmwareJun 17, 2026 Apr 4, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands are executed using pre-login execution...Show more |