← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Br Automation
1Industrial Automation Aprol
Jun 17, 2026
Nov 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerab...Show more
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019-16364.Show less
1Br Automation
1Industrial Automation Aprol
Jun 17, 2026
Nov 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerabilit...Show more
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerability than CVE-2019-16364.Show less
1Qnap
1Qts
Jun 17, 2026
Nov 16, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
1Qnap
1Qts
Jun 17, 2026
Nov 16, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
1Huawei
6Nip6300 Firmware
Nip6600 FirmwareSecospace Usg6300 Firmware+3 more
Jun 17, 2026
Nov 13, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploi...Show more
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command injection.Affected product versions include:NIP6300 versions V500R001C30,V500R001C60;NIP6600 versions V500R001C30,V500R001C60;Secospace USG6300 versions V500R001C30,V500R001C60;Secospace USG6500 versions V500R001C30,V500R001C60;Secospace USG6600 versions V500R001C30,V500R001C60;USG9500 versions V500R001C30,V500R001C60.Show less
1Moxa
1Vport 461 Firmware
Jun 17, 2026
Nov 2, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers.
1Qnap
1Music Station
Nov 21, 2024
Nov 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versio...Show more
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.Show less
1Rapid7
1Metasploit
Jun 17, 2026
Oct 29, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
1Qnap
1Qts
Nov 3, 2025
Oct 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201...Show more
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.Show less
1Verifone
1Mx900 Firmware
Jun 17, 2026
Oct 23, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.
1Sprecher Automation
1Sprecon E
Jun 17, 2026
Oct 19, 2020
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks the validation of the input values on the device side, which is provide...Show more
Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks the validation of the input values on the device side, which is provided by the engineering software during parameterization. Attackers with access to local configuration files can therefore insert malicious commands that are executed after compiling them to valid parameter files (“PDLs”), transferring them to the device, and restarting the device.Show less
1Apple
7Icloud
IpadosIphone Os+4 more
Jun 17, 2026
Oct 16, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows,...Show more
A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Copying a URL from Web Inspector may lead to command injection.Show less
1Ibm
1Resilient Security Orchestration Automation And Response
Jun 17, 2026
Oct 16, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.
1Netgear
2R6220 Firmware
R6230 Firmware
Jun 17, 2026
Oct 9, 2020
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.
1Netgear
4Wc7500 Firmware
Wc7600 FirmwareWc7600v2 Firmware+1 more
Jun 17, 2026
Oct 9, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24.
1Netgear
3Srk60 Firmware
Srr60 FirmwareSrs60 Firmware
Jun 17, 2026
Oct 9, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.3.110, SRR60 before 2.5.3.110, and SRS60 before 2.5.3.110.
1Netgear
14D6200 Firmware
D7000 FirmwareJr6150 Firmware+11 more
Jun 17, 2026
Oct 9, 2020
N/A· v4
7.1 HIGH· v3
5.2 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080...Show more
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.Show less
1Netgear
7Cbr40 Firmware
Rbk752 FirmwareRbk852 Firmware+4 more
Jun 17, 2026
Oct 9, 2020
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25,...Show more
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.Show less
1Netgear
2D7800 Firmware
R7500v2 Firmware
Jun 17, 2026
Oct 9, 2020
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.58 and R7500v2 before 1.0.3.48.
1Netgear
3Rbk852 Firmware
Rbr850 FirmwareRbs850 Firmware
Jun 17, 2026
Oct 9, 2020
N/A· v4
8.8 HIGH· v3
7.7 HIGH· v2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.