← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the week parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the recHour parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the mode parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the hour parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the dhcpMtu parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the ttlWay parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunPort parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun_user parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the url parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the provider parameter to /cgi-bin/cstecgi.cgi.
1Totolink
1A3300r Firmware
Jun 17, 2026
Apr 23, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password parameter to /cgi-bin/cstecgi.cgi.
1Wwbn
1Avideo
Jun 17, 2026
Apr 22, 2026
8.9 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper...Show more
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection. An attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to Remote Code Execution (RCE) on the server. Commit 473c609fc2defdea8b937b00e86ce88eba1f15bb contains a fix.Show less
-
-
Jun 17, 2026
Apr 21, 2026
2.1 LOW· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component Endpoint. Performing a...Show more
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component Endpoint. Performing a manipulation of the argument destination results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Tenda
1W30e Firmware
Jun 17, 2026
Apr 21, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary co...Show more
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Tenda
1W30e Firmware
Jun 17, 2026
Apr 21, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafte...Show more
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less