CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 48 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0315 | Hig | 0.61 | 8.8 | 0.98 | Jan 16, 2023 | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | ||
| CVE-2020-28453 | Cri | 0.61 | 9.4 | 0.01 | Aug 2, 2022 | This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js. | ||
| CVE-2020-28437 | Cri | 0.61 | 9.4 | 0.01 | Aug 2, 2022 | This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js. | ||
| CVE-2020-28434 | Cri | 0.61 | 9.4 | 0.01 | Aug 2, 2022 | This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js. | ||
| CVE-2020-28435 | Cri | 0.61 | 9.4 | 0.01 | Jul 25, 2022 | This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js. | ||
| CVE-2021-43339 | Hig | 0.61 | 8.8 | 0.10 | Nov 3, 2021 | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created. | ||
| CVE-2020-35798 | Cri | 0.61 | 9.3 | 0.01 | Dec 30, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900… | ||
| CVE-2019-6275 | Hig | 0.61 | 8.8 | 0.13 | Mar 21, 2019 | Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. | ||
| CVE-2019-6272 | Hig | 0.61 | 8.8 | 0.13 | Mar 21, 2019 | Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. | ||
| CVE-2017-6048 | Hig | 0.61 | 8.8 | 0.16 | May 19, 2017 | A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this… | ||
| CVE-2016-0861 | Hig | 0.61 | 8.8 | 0.14 | Feb 5, 2016 | General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors. | ||
| CVE-2026-52806 | Cri | 0.60 | 9.9 | 0.01 | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during… | ||
| CVE-2026-41090 | Cri | 0.60 | 9.3 | 0.00 | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2026-44257 | Cri | 0.60 | — | 0.00 | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and… | ||
| CVE-2026-3854 | Hig | 0.60 | 8.8 | 0.34 | Mar 10, 2026 | An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were… | ||
| CVE-2025-59286 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-59272 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | ||
| CVE-2025-59252 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-61584 | Cri | 0.60 | — | 0.00 | Sep 30, 2025 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the… | ||
| CVE-2025-50989 | Cri | 0.60 | 9.1 | 0.08 | Aug 27, 2025 | OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowing an… |
- risk 0.61cvss 8.8epss 0.98
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
- risk 0.61cvss 8.8epss 0.10
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.
- risk 0.61cvss 9.3epss 0.01
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900…
- risk 0.61cvss 8.8epss 0.13
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
- risk 0.61cvss 8.8epss 0.13
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
- risk 0.61cvss 8.8epss 0.16
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this…
- risk 0.61cvss 8.8epss 0.14
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.
- risk 0.60cvss 9.9epss 0.01
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during…
- risk 0.60cvss 9.3epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
- risk 0.60cvss —epss 0.00
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and…
- risk 0.60cvss 8.8epss 0.34
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were…
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.60cvss —epss 0.00
serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the…
- risk 0.60cvss 9.1epss 0.08
OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowing an…