CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app...Show more |
1Juniper 1Northstar Controller May 13, 2026 Apr 24, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition. |
1Netgear 7Wn604 Firmware Wn802tv2 FirmwareWnap320 Firmware+4 moreApr 22, 2026 Apr 21, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5....Show more |
1Solarwinds 1Log & Event Manager May 13, 2026 Apr 12, 2017 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in...Show more |
1Schneider Electric 1Homelynk Controller Lss100100 Firmware May 13, 2026 Apr 11, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0. |
2Redhat Setroubleshoot Project5Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+2 moreMay 13, 2026 Apr 11, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux denial with a crafted file name, which is handled by the _set_tpath funct...Show more |
2Redhat Setroubleshoot Project5Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+2 moreMay 13, 2026 Apr 11, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput function. |
2Redhat Setroubleshoot Project5Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+2 moreMay 13, 2026 Apr 11, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external comma...Show more |
2Redhat Setroubleshoot Project5Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+2 moreMay 13, 2026 Apr 11, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the commands.getstatusoutput f...Show more |
Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php. |
1Opmantek 1Network Management Information System May 13, 2026 Apr 10, 2017 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G might be affected in non-default configurations. |
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection. |
1Sierrawireless 1Aleos Firmware May 13, 2026 Apr 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection. |
1Jensenofscandinavia 3Al3g Firmware Al5000ac FirmwareAl59300 FirmwareMay 13, 2026 Apr 3, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to execute arbitrary commands...Show more |
1Huawei 1Oceanstor 5600 V3 Firmware May 13, 2026 Apr 2, 2017 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Huawei OceanStor 5600 V3 with V300R003C00C10 and earlier versions allows attackers with administrator privilege to inject a command into a specific command's parameters, and run this injected command with root privilege. |
3Fedoraproject KernelOpensuse3Fedora OpensuseUtil LinuxMay 13, 2026 Mar 31, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code. |
3Nagios RedhatSnoopy3Nagios OpenstackSnoopyMay 13, 2026 Mar 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008. |
3Debian RedhatSnoopy3Debian Linux OpenstackSnoopyMay 13, 2026 Mar 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Snoopy allows remote attackers to execute arbitrary commands. |
3Nagios RedhatSnoopy3Nagios OpenstackSnoopyMay 13, 2026 Mar 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796. |
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303. |