CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter. |
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a craft...Show more |
1Tendacn 2G1 Firmware G3 FirmwareJun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name...Show more |
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. |
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter F...Show more |
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host...Show more |
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST r...Show more |
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP...Show more |
1Dlink 2Dir 878 Firmware Dir 882 FirmwareJun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execu...Show more |
1Totolink 3A3100r Firmware A720r FirmwareA830r FirmwareJun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability al...Show more |
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution. |
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds. |
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage. |
1Dell 3Emc Unity Operating Environment Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating EnvironmentJun 17, 2026 Jan 24, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially...Show more |
1Lexmark 118B2236 Firmware B2338 FirmwareB2442 Firmware+115 moreJun 17, 2026 Jan 20, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07. |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Jan 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability....Show more |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Jan 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability....Show more |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Jan 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use th...Show more |
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for inter...Show more |
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can inse...Show more |