CWE-77
3,801 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,801)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Commscope 1Arris Tr3300 Firmware Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. |
1Commscope 1Arris Tr3300 Firmware Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execut...Show more |
1Commscope 1Arris Tr3300 Firmware Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_mask, pptp_fix_gw, and wan_dns1_stat parameters. This vulnerability allo...Show more |
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters. |
1Tp Link 1Tapo C200 Firmware Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability...Show more |
An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Seri...Show more |
Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Ser...Show more |
1C Data Onu4ferw Project 1C Data Onu4ferw Firmware Jun 17, 2026 Feb 25, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file. |
1Huawei 1Ais Bw80h 00 Firmware Jun 17, 2026 Feb 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the...Show more |
1Honeywell 2Hbw2per1 Firmware Hdzp252di FirmwareJun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved. |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbi...Show more |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitra...Show more |
A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. |
A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. |
A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execu...Show more |
1Totolink 2T10 Firmware T6 FirmwareJun 17, 2026 Feb 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrar...Show more |
4Cobbler Project FedoraprojectOpensuse+1 more5Backports CobblerFactory+2 moreJun 17, 2026 Feb 19, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginni...Show more |
A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client con...Show more |