CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Samba Client Project 1Samba Client Jun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec. |
1Wavlink 2Wn575a4 Firmware Wn579x3 FirmwareJun 17, 2026 Feb 9, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request. |
1Hpe 1Baseboard Management Controller Jun 17, 2026 Feb 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function. |
1Hpe 1Baseboard Management Controller Jun 17, 2026 Feb 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function. |
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Hel...Show more |
In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...Show more |
In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...Show more |
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...Show more |
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...Show more |
1Adt 1Lifeshield Diy Hd Video Doorbell Firmware Jun 17, 2026 Feb 2, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on th...Show more |
1Cisco 4Catalyst Sd Wan Manager Sd Wan FirmwareSd Wan Vbond Orchestrator+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more |
1Cisco 4Catalyst Sd Wan Manager Sd Wan FirmwareSd Wan Vbond Orchestrator+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more |
1Cisco 4Catalyst Sd Wan Manager Sd Wan FirmwareSd Wan Vbond Orchestrator+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more |
1Cisco 4Catalyst Sd Wan Manager Sd Wan FirmwareSd Wan Vbond Orchestrator+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more |
1Cisco 4Catalyst Sd Wan Manager Sd Wan FirmwareSd Wan Vbond Orchestrator+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more |
1Cisco 4Catalyst Sd Wan Manager Sd Wan FirmwareSd Wan Vbond Orchestrator+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more |
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700. |
1Mi 2Ax1800 Firmware Rm1800 FirmwareJun 17, 2026 Jan 13, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800...Show more |
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this...Show more |
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execu...Show more |