← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.
1Totolink
1N600r Firmware
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
1Totolink
1N600r Firmware
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.
1Totolink
1N600r Firmware
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.
1Totolink
1N600r Firmware
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.
1Garo
3Wallbox Glb Firmware
Wallbox Gtb FirmwareWallbox Gtc Firmware
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is...Show more
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary co...Show more
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a craf...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execut...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_mask, pptp_fix_gw, and wan_dns1_stat parameters. This vulnerability allo...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_mask, pptp_fix_gw, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Totolink
1A3100r Firmware
Jul 9, 2026
Mar 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.