← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
Jun 17, 2026
Aug 16, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.
1Dcce
1Mac1100 Plc Firmware
Jun 17, 2026
Aug 13, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
1Netgear
10Rbk20 Firmware
Rbk40 FirmwareRbk50 Firmware+7 more
Jun 17, 2026
Aug 11, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RB...Show more
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.Show less
1Netgear
4D7800 Firmware
R7800 FirmwareR8900 Firmware+1 more
Jun 17, 2026
Aug 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.
1Netgear
6D8500 Firmware
R6900p FirmwareR7000p Firmware+3 more
Jun 17, 2026
Aug 11, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1...Show more
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1.0.1.38, and XR300 before 1.0.3.56.Show less
1Netgear
34Cbr40 Firmware
Ex6100 FirmwareEx6150 Firmware+31 more
Jun 17, 2026
Aug 11, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.98, EX6150v2 before 1.0.1.98, EX6250 before 1.0.0.132, EX6400 before 1.0...Show more
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.98, EX6150v2 before 1.0.1.98, EX6250 before 1.0.0.132, EX6400 before 1.0.2.158, EX6400v2 before 1.0.0.132, EX6410 before 1.0.0.132, EX6420 before 1.0.0.132, EX7300 before 1.0.2.158, EX7300v2 before 1.0.0.132, EX7320 before 1.0.0.132, EX7700 before 1.0.0.216, EX8000 before 1.0.1.232, R7800 before 1.0.2.78, RBK12 before 2.6.1.44, RBR10 before 2.6.1.44, RBS10 before 2.6.1.44, RBK20 before 2.6.1.38, RBR20 before 2.6.1.36, RBS20 before 2.6.1.38, RBK40 before 2.6.1.38, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBS40V before 2.6.2.4, RBS50Y before 2.6.1.40, RBW30 before 2.6.2.2, and XR500 before 2.3.2.114.Show less
1Netgear
5R6400 Firmware
R7900p FirmwareR8000p Firmware+2 more
Jun 17, 2026
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50, R7900P before 1.4.1.50, R8000P before 1.4.1.50, RAX75 before 1.0.1.62, and RAX80 before 1.0.1.62.
1Netgear
4R6400 Firmware
R6700 FirmwareR6900 Firmware+1 more
Jun 17, 2026
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62,...Show more
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, and R7000P before 1.3.2.124.Show less
1Netgear
14R6250 Firmware
R6300 FirmwareR6400 Firmware+11 more
Jun 17, 2026
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6...Show more
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6700 before 1.0.2.8, R6900 before 1.0.2.8, R7000 before 1.0.9.88, R6900P before 1.3.2.132, R7100LG before 1.0.0.52, R7900 before 1.0.3.10, R8000 before 1.0.4.46, R7900P before 1.4.1.50, R8000P before 1.4.1.50, and RAX80 before 1.0.1.40.Show less
1Netgear
6Rax200 Firmware
Rax75 FirmwareRax80 Firmware+3 more
Jun 17, 2026
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12,...Show more
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.Show less
1Kde
1Kmail
Jun 17, 2026
Aug 10, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
1Kde
1Trojita
Jun 17, 2026
Aug 10, 2021
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.
1Alpine Project
1Alpine
Jun 17, 2026
Aug 10, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
1Lettre
1Lettre
Jun 17, 2026
Aug 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands.
1Multiqueue Project
1Multiqueue
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>.
1Syncpool Project
1Syncpool
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2.
1Noise Search Project
1Noise Search
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock.
1Dces Project
1Dces
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore.
1Lever Project
1Lever
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for all types T.
1Toolshed Project
1Toolshed
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds on the contained type.