CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a
The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the
Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Commo
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script.
codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync com
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute
The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 functio
ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName param
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a comm
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during
Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and shor
Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau
A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESE
A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/ht
A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbi
Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary argume
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE con
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on ho
Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automat
goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without a
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware befo
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at
YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.
An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.2
An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink AC3000 M33A8.V5030.210
An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000
Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC300
Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC300
Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC300
Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC300
Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5
Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5
Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inje
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started