← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dlink
1Di 7200gv2 Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.
1Dlink
1Dir 882 Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a craft...Show more
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.Show less
1Tendacn
2G1 Firmware
G3 Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name...Show more
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.Show less
1Totolink
1A720r Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
1Totolink
1X5000r Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter F...Show more
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.Show less
1Totolink
1X5000r Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host...Show more
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.Show less
1Dlink
1Dir 878 Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST r...Show more
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.Show less
1Dlink
1Dir 882 Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP...Show more
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.Show less
1Dlink
2Dir 878 Firmware
Dir 882 Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execu...Show more
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.Show less
1Totolink
3A3100r Firmware
A720r FirmwareA830r Firmware
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability al...Show more
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.Show less
1Printerlogic
1Web Stack
Jul 9, 2026
Feb 1, 2022
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.
1Gerapy
1Gerapy
Jun 17, 2026
Jan 26, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.
1Moxa
1Tn 5900 Firmware
Jun 17, 2026
Jan 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.
1Dell
3Emc Unity Operating Environment
Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating Environment
Jun 17, 2026
Jan 24, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially...Show more
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the Unity underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.Show less
1Lexmark
118B2236 Firmware
B2338 FirmwareB2442 Firmware+115 more
Jun 17, 2026
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
1Chinamobile
1An Lianbao Wf 1 Firmware
Jun 17, 2026
Jan 18, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability....Show more
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.Show less
1Chinamobile
1An Lianbao Wf 1 Firmware
Jun 17, 2026
Jan 18, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability....Show more
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.Show less
1Chinamobile
1An Lianbao Wf 1 Firmware
Jun 17, 2026
Jan 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use th...Show more
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.Show less
1Westerndigital
1My Cloud Os
Jun 17, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for inter...Show more
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for internet connectivity using HTTP.Show less
1Mitre
1Caldera
Jun 17, 2026
Jan 12, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can inse...Show more
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.Show less