CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,970)
page 49 of 199| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5878 | Cri | 0.61 | — | 0.01 | Feb 6, 2025 | Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the… | ||
| CVE-2024-37186 | Cri | 0.61 | 9.1 | 0.23 | Jan 14, 2025 | An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | ||
| CVE-2024-7397 | Cri | 0.61 | — | 0.01 | Aug 5, 2024 | Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2. | ||
| CVE-2024-38492 | Cri | 0.61 | — | 0.01 | Jul 15, 2024 | This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file. | ||
| CVE-2023-1097 | Cri | 0.61 | 9.3 | 0.01 | Mar 1, 2023 | Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated… | ||
| CVE-2023-0315 | Hig | 0.61 | 8.8 | 0.98 | Jan 16, 2023 | Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8. | ||
| CVE-2020-28453 | Cri | 0.61 | 9.4 | 0.01 | Aug 2, 2022 | This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js. | ||
| CVE-2020-28437 | Cri | 0.61 | 9.4 | 0.01 | Aug 2, 2022 | This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js. | ||
| CVE-2020-28434 | Cri | 0.61 | 9.4 | 0.01 | Aug 2, 2022 | This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js. | ||
| CVE-2020-28435 | Cri | 0.61 | 9.4 | 0.01 | Jul 25, 2022 | This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js. | ||
| CVE-2021-43339 | Hig | 0.61 | 8.8 | 0.10 | Nov 3, 2021 | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created. | ||
| CVE-2020-35798 | Cri | 0.61 | 9.3 | 0.01 | Dec 30, 2020 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900… | ||
| CVE-2019-6275 | Hig | 0.61 | 8.8 | 0.13 | Mar 21, 2019 | Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. | ||
| CVE-2019-6272 | Hig | 0.61 | 8.8 | 0.13 | Mar 21, 2019 | Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code. | ||
| CVE-2017-6048 | Hig | 0.61 | 8.8 | 0.16 | May 19, 2017 | A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this… | ||
| CVE-2016-0861 | Hig | 0.61 | 8.8 | 0.14 | Feb 5, 2016 | General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors. | ||
| CVE-2026-41090 | Cri | 0.60 | 9.3 | 0.00 | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2026-44257 | Cri | 0.60 | — | 0.00 | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and… | ||
| CVE-2026-3854 | Hig | 0.60 | 8.8 | 0.40 | Mar 10, 2026 | An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were… | ||
| CVE-2025-59286 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. |
- risk 0.61cvss —epss 0.01
Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the…
- risk 0.61cvss 9.1epss 0.23
An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
- risk 0.61cvss —epss 0.01
Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2.
- risk 0.61cvss —epss 0.01
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
- risk 0.61cvss 9.3epss 0.01
Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated…
- risk 0.61cvss 8.8epss 0.98
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
- risk 0.61cvss 8.8epss 0.10
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.
- risk 0.61cvss 9.3epss 0.01
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900…
- risk 0.61cvss 8.8epss 0.13
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
- risk 0.61cvss 8.8epss 0.13
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
- risk 0.61cvss 8.8epss 0.16
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this…
- risk 0.61cvss 8.8epss 0.14
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.
- risk 0.60cvss 9.3epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
- risk 0.60cvss —epss 0.00
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry name such as ../../../pwned.jsp escapes the intended extraction directory and…
- risk 0.60cvss 8.8epss 0.40
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were…
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.