CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” parameter. The vulnerability could allow...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_test” value for the “feed” parameter. The vulnerability could allow a spec...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as nei...Show more |
1Inhandnetworks 1Ir302 Firmware Jun 17, 2026 May 12, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an...Show more |
1Inhandnetworks 1Ir302 Firmware Jun 17, 2026 May 12, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send...Show more |
An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence...Show more |
1F5 4Big Ip Access Policy Manager Big Ip Advanced Web Application FirewallBig Ip Application Security Manager+1 moreJun 17, 2026 May 5, 2022 N/A· v4 7.2 HIGH· v3 6.0 MEDIUM· v2 On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authent...Show more |
We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 May 5, 2022 N/A· v4 9.1 CRITICAL· v3 6.0 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x, when running in Appliance mode, an authen...Show more |
A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this...Show more |
1Cisco 4Rv340 Firmware Rv340w FirmwareRv345 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying oper...Show more |
1Cisco 4Rv340 Firmware Rv340w FirmwareRv345 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying oper...Show more |
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth. |
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose. |
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch. |
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose. |
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common.. |