CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 3D3600 Firmware D6000 FirmwareXr500 FirmwareJun 17, 2026 Apr 16, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32. |
1Netgear 3D3600 Firmware D6000 FirmwareXr500 FirmwareJun 17, 2026 Apr 16, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32. |
1Netgear 3D3600 Firmware D6000 FirmwareXr500 FirmwareJun 17, 2026 Apr 16, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32. |
1Netgear 3D3600 Firmware D6000 FirmwareXr500 FirmwareJun 17, 2026 Apr 16, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32. |
1Netgear 20D6000 Firmware D6100 FirmwareEx2700 Firmware+17 moreJun 17, 2026 Apr 16, 2020 N/A· v4 6.8 MEDIUM· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, E...Show more |
1Netgear 21D3600 Firmware D6000 FirmwareD6100 Firmware+18 moreJun 17, 2026 Apr 16, 2020 N/A· v4 6.8 MEDIUM· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX61...Show more |
1Netgear 19D7000 Firmware R6220 FirmwareR6260 Firmware+16 moreJun 17, 2026 Apr 15, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6800...Show more |
1Netgear 4R6400 Firmware R6700 FirmwareR6900 Firmware+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10. |
1Netgear 2Xr500 Firmware Xr700 FirmwareJun 17, 2026 Apr 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20. |
1Netgear 2Wac505 Firmware Wac510 FirmwareJun 17, 2026 Apr 15, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16 and WAC510 before 8.2.1.16. |
1Netgear 4R6400 Firmware R6700 FirmwareR6900 Firmware+1 moreJun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3....Show more |
1Netgear 26D6220 Firmware D6400 FirmwareD7000 Firmware+23 moreJun 17, 2026 Apr 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, R6220 before 1.1.0.80, R6250...Show more |
iCatch DVR firmware before 20200103 do not validate function parameter properly, resulting attackers executing arbitrary command. |
3Apple DebianKsh Project3Debian Linux KshMac Os XJun 17, 2026 Apr 2, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and appl...Show more |
1Netgear 5Wc7500 Firmware Wc7520 FirmwareWc7600v1 Firmware+2 moreNov 21, 2024 Apr 1, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running fir...Show more |
1Vertiv 1Avocent Umg 4000 Firmware Jun 17, 2026 Mar 30, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web applica...Show more |
1Draytek 3Vigor2960 Firmware Vigor300b FirmwareVigor3900 FirmwareJun 17, 2026 Mar 26, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode. |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Mar 25, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a te...Show more |
A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient inpu...Show more |
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI im...Show more |