← Back
CWE-77

3,801 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,801)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Diskstation Manager
Jun 17, 2026
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users...Show more
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.Show less
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.
1Totolink
1N600r Firmware
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.
1Totolink
1N600r Firmware
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.
1Totolink
1N600r Firmware
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.
1Totolink
1N600r Firmware
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.
1Garo
3Wallbox Glb Firmware
Wallbox Gtb FirmwareWallbox Gtc Firmware
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is...Show more
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary co...Show more
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Commscope
1Arris Tr3300 Firmware
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a craf...Show more
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less