← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asus
7Ea N66 Firmware
Rp Ac52 FirmwareRp Ac56 Firmware+4 more
Nov 21, 2024
Jul 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script paramet...Show more
A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script parameter specifies a script to be executed if the action_mode parameter does not contain a valid state. If the input provided by action_script does not match one of the hard coded options, then it will be executed as the argument of either a system() or an eval() call allowing arbitrary commands to be executed.Show less
1Microsoft
1Wireless Display Adapter Firmware
Jun 17, 2026
Jul 11, 2018
N/A· v4
5.5 MEDIUM· v3
5.2 MEDIUM· v2
A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not properly manage user input, aka "Microsoft Wireless Display Adapter Command I...Show more
A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not properly manage user input, aka "Microsoft Wireless Display Adapter Command Injection Vulnerability." This affects Microsoft Wireless Display Adapter V2 Software.Show less
1Schneider Electric
1U.motion Builder
Jun 17, 2026
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.
1Dell
3Idrac7 Firmware
Idrac8 FirmwareIdrac9 Firmware
Nov 21, 2024
Jul 2, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration pr...Show more
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration privileges could potentially exploit this vulnerability to execute arbitrary commands on the iDRAC where SNMP alerting is enabled.Show less
1Dell
2Idrac6 Modular
Idrac6 Monolithic
Nov 21, 2024
Jul 2, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the...Show more
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as root on the affected iDRAC system.Show less
1Microfocus
1Secure Messaging Gateway
Nov 21, 2024
Jun 29, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the...Show more
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).Show less
1Qnap
1Qts
Nov 21, 2024
Jun 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or ins...Show more
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.Show less
1Tibco
1Data Virtualization
Jun 17, 2026
Jun 20, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution. Affected releases are TIBCO Data V...Show more
The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution. Affected releases are TIBCO Data Virtualization: 7.0.5; 7.0.6.Show less
1Opensuse
1Sysconfig
Nov 21, 2024
Jun 12, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.
2Mdadm Project
Opensuse
2Mdadm
Opensuse
Nov 21, 2024
Jun 8, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
1Synology
1Router Manager
Nov 21, 2024
Jun 8, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitrary command via the username parameter.
1Synology
1Diskstation Manager
Jan 14, 2025
Jun 8, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter.
1Dns Sync Project
1Dns Sync
Nov 21, 2024
Jun 7, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
1Pdfinfojs Project
1Pdfinfojs
Nov 21, 2024
Jun 1, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
1Sudo Project
1Sudo
Nov 21, 2024
May 29, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such ap...Show more
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.Show less
2Fedoraproject
Redhat
7Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Nov 21, 2024
May 17, 2018
N/A· v4
7.5 HIGH· v3
7.9 HIGH· v2
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an at...Show more
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.Show less
1Cisco
1Network Functions Virtualization Infrastructure
Nov 21, 2024
May 17, 2018
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insuffic...Show more
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters in the CLI parser. An attacker could exploit this vulnerability by invoking a vulnerable CLI command with crafted malicious parameters. An exploit could allow the attacker to execute arbitrary commands with a non-root user account on the underlying Linux operating system of the affected device. Cisco Bug IDs: CSCvi09723.Show less
1Tinywebgallery
1Wordpress Flash Uploader
Nov 21, 2024
Apr 25, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
1Foscam
1C1 Firmware
Nov 21, 2024
Apr 24, 2018
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user t...Show more
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters resulting in command injection during the boot process. To trigger this vulnerability, an attacker needs to send an HTTP request and reboot the device.Show less
1Foscam
1C1 Firmware
Nov 21, 2024
Apr 24, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user t...Show more
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during a password change resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.Show less