← Back
CWE-77

3,801 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,801)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Iptime
1C200 Firmware
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cook...Show more
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cookie value.Show less
1Netgear
19Ac2100 Firmware
Ac2400 FirmwareAc2600 Firmware+16 more
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.8 MEDIUM· v3
7.7 HIGH· v2
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, a...Show more
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. When parsing the funjsq_access_token parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11653.Show less
1Dlink
1Dap 1860 Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerab...Show more
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the Authorization request header, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-10880.Show less
1Dlink
2Dsl 2888a Firmware
Dva 2800 Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specifi...Show more
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on TCP port 8008 by default. When parsing the path parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-10911.Show less
1Samba Client Project
1Samba Client
Jun 17, 2026
Feb 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.
1Wavlink
2Wn575a4 Firmware
Wn579x3 Firmware
Jun 17, 2026
Feb 9, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
1Hpe
1Baseboard Management Controller
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.
1Hpe
1Baseboard Management Controller
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.
1Qnap
1Helpdesk
Jun 17, 2026
Feb 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Hel...Show more
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.Show less
1Google
1Android
Jun 17, 2026
Feb 3, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...Show more
In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05458478; Issue ID: ALPS05458503.Show less
1Google
1Android
Jun 17, 2026
Feb 3, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat...Show more
In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05458478.Show less
1Google
1Android
Jun 17, 2026
Feb 3, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...Show more
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05442022.Show less
1Google
1Android
Jun 17, 2026
Feb 3, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...Show more
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11; Patch ID: ALPS05442014.Show less
1Adt
1Lifeshield Diy Hd Video Doorbell Firmware
Jun 17, 2026
Feb 2, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on th...Show more
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on the device. This issue affects: ADT LifeShield DIY HD Video Doorbell version 1.0.02R09 and prior versions.Show less
1Cisco
4Catalyst Sd Wan Manager
Sd Wan FirmwareSd Wan Vbond Orchestrator+1 more
Jun 17, 2026
Jan 20, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
4Catalyst Sd Wan Manager
Sd Wan FirmwareSd Wan Vbond Orchestrator+1 more
Jun 17, 2026
Jan 20, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
4Catalyst Sd Wan Manager
Sd Wan FirmwareSd Wan Vbond Orchestrator+1 more
Jun 17, 2026
Jan 20, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
4Catalyst Sd Wan Manager
Sd Wan FirmwareSd Wan Vbond Orchestrator+1 more
Jun 17, 2026
Jan 20, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
4Catalyst Sd Wan Manager
Sd Wan FirmwareSd Wan Vbond Orchestrator+1 more
Jun 17, 2026
Jan 20, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
4Catalyst Sd Wan Manager
Sd Wan FirmwareSd Wan Vbond Orchestrator+1 more
Jun 17, 2026
Jan 20, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root pr...Show more
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these vulnerabilities, see the Details section of this advisory.Show less