CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tp Link 1Tapo C200 Firmware Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability...Show more |
An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Seri...Show more |
Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Ser...Show more |
1C Data Onu4ferw Project 1C Data Onu4ferw Firmware Jun 17, 2026 Feb 25, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file. |
1Huawei 1Ais Bw80h 00 Firmware Jun 17, 2026 Feb 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the...Show more |
1Honeywell 2Hbw2per1 Firmware Hdzp252di FirmwareJun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved. |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbi...Show more |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitra...Show more |
A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. |
A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. |
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execu...Show more |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrar...Show more |
4Cobbler Project FedoraprojectOpensuse+1 more5Backports CobblerFactory+2 moreJun 17, 2026 Feb 19, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginni...Show more |
A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client con...Show more |
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and b...Show more |
1Commscope 5Arris Surfboard Sbg10 Firmware Arris Surfboard Sbg6950ac2 FirmwareArris Surfboard Sbg7400ac2 Firmware+2 moreJun 17, 2026 Feb 15, 2022 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection. |
1Enterprisedt 1Completeftp Server Jun 17, 2026 Feb 14, 2022 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM. |
1Tendacn 2G1 Firmware G3 FirmwareJun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppo...Show more |