CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 82 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-34259 | Hig | 0.53 | 8.2 | 0.00 | May 12, 2026 | Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the… | ||
| CVE-2026-20761 | Hig | 0.53 | 8.1 | 0.01 | Feb 20, 2026 | A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device. | ||
| CVE-2025-67089 | Hig | 0.53 | 8.1 | 0.01 | Jan 8, 2026 | A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute… | ||
| CVE-2025-60595 | Hig | 0.53 | 8.2 | 0.00 | Oct 29, 2025 | SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. | ||
| CVE-2025-60801 | Hig | 0.53 | 8.2 | 0.00 | Oct 24, 2025 | jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function. | ||
| CVE-2025-53787 | Hig | 0.53 | 8.2 | 0.01 | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | ||
| CVE-2025-52690 | — | Hig | 0.53 | 8.1 | 0.10 | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point. | |
| CVE-2025-7097 | Hig | 0.53 | 8.1 | 0.05 | Jul 6, 2025 | A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown processing of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation of the argument binary/params… | ||
| CVE-2025-43858 | Cri | 0.53 | 9.2 | 0.00 | Apr 24, 2025 | YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt… | ||
| CVE-2025-2725 | Hig | 0.53 | 8.0 | 0.08 | Mar 25, 2025 | A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The… | ||
| CVE-2025-0798 | Hig | 0.53 | 8.1 | 0.07 | Jan 29, 2025 | A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command injection. The attack may be… | ||
| CVE-2024-57539 | Hig | 0.53 | 8.2 | 0.01 | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail. | ||
| CVE-2024-57036 | Hig | 0.53 | 8.1 | 0.01 | Jan 21, 2025 | TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request. | ||
| CVE-2024-27980 | — | Hig | 0.53 | 8.1 | 0.01 | Jan 9, 2025 | Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled. | |
| CVE-2024-48288 | Hig | 0.53 | 8.0 | 0.10 | Nov 21, 2024 | TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend. | ||
| CVE-2024-48286 | Hig | 0.53 | 8.0 | 0.12 | Nov 21, 2024 | Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function. | ||
| CVE-2024-52739 | Hig | 0.53 | 8.0 | 0.09 | Nov 20, 2024 | D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters. | ||
| CVE-2024-28726 | Hig | 0.53 | 8.0 | 0.08 | Nov 12, 2024 | An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function. | ||
| CVE-2024-36138 | Hig | 0.53 | 8.1 | 0.01 | Sep 7, 2024 | Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even… | ||
| CVE-2024-24550 | Hig | 0.53 | 8.1 | 0.01 | Jun 24, 2024 | A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads,… |
- risk 0.53cvss 8.2epss 0.00
Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbitrary operating system commands. Successful exploitation could allow the…
- risk 0.53cvss 8.1epss 0.01
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.
- risk 0.53cvss 8.1epss 0.01
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute…
- risk 0.53cvss 8.2epss 0.00
SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.
- risk 0.53cvss 8.2epss 0.00
jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.
- risk 0.53cvss 8.2epss 0.01
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
- risk 0.53cvss 8.1epss 0.10
Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.
- risk 0.53cvss 8.1epss 0.05
A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown processing of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation of the argument binary/params…
- risk 0.53cvss 9.2epss 0.00
YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt…
- risk 0.53cvss 8.0epss 0.08
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The…
- risk 0.53cvss 8.1epss 0.07
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command injection. The attack may be…
- risk 0.53cvss 8.2epss 0.01
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.
- risk 0.53cvss 8.1epss 0.01
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.
- risk 0.53cvss 8.1epss 0.01
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
- risk 0.53cvss 8.0epss 0.10
TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.
- risk 0.53cvss 8.0epss 0.12
Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
- risk 0.53cvss 8.0epss 0.09
D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.
- risk 0.53cvss 8.0epss 0.08
An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function.
- risk 0.53cvss 8.1epss 0.01
Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even…
- risk 0.53cvss 8.1epss 0.01
A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads,…