CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Br Automation 1Industrial Automation Aprol Jun 17, 2026 Nov 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerab...Show more |
1Br Automation 1Industrial Automation Aprol Jun 17, 2026 Nov 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerabilit...Show more |
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907. |
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907. |
1Huawei 6Nip6300 Firmware Nip6600 FirmwareSecospace Usg6300 Firmware+3 moreJun 17, 2026 Nov 13, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploi...Show more |
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers. |
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versio...Show more |
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine. |
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201...Show more |
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager. |
1Sprecher Automation 1Sprecon E Jun 17, 2026 Oct 19, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks the validation of the input values on the device side, which is provide...Show more |
1Apple 7Icloud IpadosIphone Os+4 moreJun 17, 2026 Oct 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows,...Show more |
1Ibm 1Resilient Security Orchestration Automation And Response Jun 17, 2026 Oct 16, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503. |
1Netgear 2R6220 Firmware R6230 FirmwareJun 17, 2026 Oct 9, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100. |
1Netgear 4Wc7500 Firmware Wc7600 FirmwareWc7600v2 Firmware+1 moreJun 17, 2026 Oct 9, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24. |
1Netgear 3Srk60 Firmware Srr60 FirmwareSrs60 FirmwareJun 17, 2026 Oct 9, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.3.110, SRR60 before 2.5.3.110, and SRS60 before 2.5.3.110. |
1Netgear 14D6200 Firmware D7000 FirmwareJr6150 Firmware+11 moreJun 17, 2026 Oct 9, 2020 N/A· v4 7.1 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080...Show more |
1Netgear 7Cbr40 Firmware Rbk752 FirmwareRbk852 Firmware+4 moreJun 17, 2026 Oct 9, 2020 N/A· v4 6.8 MEDIUM· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25,...Show more |
1Netgear 2D7800 Firmware R7500v2 FirmwareJun 17, 2026 Oct 9, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.58 and R7500v2 before 1.0.3.48. |
1Netgear 3Rbk852 Firmware Rbr850 FirmwareRbs850 FirmwareJun 17, 2026 Oct 9, 2020 N/A· v4 8.8 HIGH· v3 7.7 HIGH· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6. |