← Back
CWE-77

3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,618)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mediatek
2En7528 Firmware
En7580 Firmware
Jun 17, 2026
Feb 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User i...Show more
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
Feb 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.
1Create Choo App3 Project
1Create Choo App3
Jun 17, 2026
Feb 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
1Totolink
1T8 Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
1T8 Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
1T8 Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.
1Totolink
1T8 Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
1T8 Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
1T8 Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
1T8 Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function.
1Totolink
1Ca300 Poe Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.