CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 42 of 83
- CVE-2023-46416CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.
- CVE-2023-46417CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.
- CVE-2023-46418CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.
- CVE-2023-46419CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.
- CVE-2023-46420CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.
- CVE-2023-46421CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.
- CVE-2023-46422CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.
- CVE-2023-46423CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.
- CVE-2023-46424CRITICALCVSS 9.8EG 9.82023-10-25
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.
- CVE-2023-46484CRITICALCVSS 9.8EG 9.82023-10-31
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.
- CVE-2023-46485CRITICALCVSS 9.8EG 9.82023-10-31
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.
- CVE-2023-46574CRITICALCVSS 9.8EG 9.82023-10-25
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
- CVE-2023-46687CRITICALCVSS 9.8EG 9.82024-02-09
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.
- CVE-2023-46976CRITICALCVSS 9.8EG 9.82023-10-31
TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.
- CVE-2023-46979CRITICALCVSS 9.8EG 9.82023-10-31
TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.
- CVE-2023-46993CRITICALCVSS 9.8EG 9.82023-10-31
In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.
- CVE-2023-47104CRITICALCVSS 9.8EG 9.82023-10-30
tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, wh…
- CVE-2023-47218CRITICALCVSS 5.8EG 9.02024-02-13
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the …
- CVE-2023-47253CRITICALCVSS 9.8EG 9.82023-11-06
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.
- CVE-2023-47268MEDIUMCVSS 5.3EG 5.32026-05-08
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.
- CVE-2023-47356HIGHCVSS 8.8EG 8.82025-07-17
Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameter at /log/fw_security.mds.
- CVE-2023-47560HIGHCVSS 8.8EG 8.82024-01-05
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version…
- CVE-2023-47562HIGHCVSS 7.4EG 7.42024-02-02
An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following v…
- CVE-2023-47563HIGHCVSS 7.4EG 7.42024-09-06
An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following v…
- CVE-2023-47576HIGHCVSS 8.8EG 8.82023-12-13
An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.
- CVE-2023-4797HIGHCVSS 7.2EG 7.22024-01-16
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
- CVE-2023-48702HIGHCVSS 7.2EG 7.22023-12-13
Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file using `ProcessStartInfo` via the `ValidateVersion` function. A malicious administrator can…
- CVE-2023-48791HIGHCVSS 8.8EG 8.82023-12-13
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to e…
- CVE-2023-48801CRITICALCVSS 9.8EG 9.82023-12-01
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command exec…
- CVE-2023-48842CRITICALCVSS 9.8EG 9.82023-12-01
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.
- CVE-2023-49040CRITICALCVSS 9.8EG 9.82023-11-27
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.
- CVE-2023-49133HIGHCVSS 8.1EG 8.12024-04-09
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build …
- CVE-2023-49134HIGHCVSS 8.1EG 8.12024-04-09
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build …
- CVE-2023-49210CRITICALCVSS 9.8EG 9.82023-11-23
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnera…
- CVE-2023-49213HIGHCVSS 8.8EG 8.82023-11-23
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions…
- CVE-2023-49226HIGHCVSS 7.2EG 7.22023-12-25
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
- CVE-2023-49237CRITICALCVSS 9.8EG 9.82024-01-09
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.
- CVE-2023-49428CRITICALCVSS 9.8EG 9.82023-12-07
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- CVE-2023-49431CRITICALCVSS 9.8EG 9.82023-12-07
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- CVE-2023-49435CRITICALCVSS 9.8EG 9.82023-12-07
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
- CVE-2023-49436CRITICALCVSS 9.8EG 9.82023-12-07
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
- CVE-2023-49437CRITICALCVSS 9.8EG 9.82023-12-07
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
- CVE-2023-49565HIGHCVSS 8.4EG 8.42025-09-18
The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly u…
- CVE-2023-4958MEDIUMCVSS 6.1EG 6.12023-12-12
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS us…
- CVE-2023-49587MEDIUMCVSS 6.4EG 6.42023-12-12
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of same or other component without user interaction over the network.
- CVE-2023-49716MEDIUMCVSS 6.9EG 6.92024-02-09
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.
- CVE-2023-49898HIGHCVSS 7.2EG 7.22023-12-15
In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisit…
- CVE-2023-49959CRITICALCVSS 9.8EG 9.82024-02-26
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename paramete…
- CVE-2023-50089CRITICALCVSS 9.8EG 9.82023-12-15
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
- CVE-2023-50274HIGHCVSS 7.8EG 7.82024-01-23
HPE OneView may allow command injection with local privilege escalation.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →