CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a
An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A succes
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27,
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing t
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutrali
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutrali
Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of
An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while crea
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbit
An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A
An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command
WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.
VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of aff
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
An attacker with access to a Management Console user account with the editor role could escalate privileges through a co
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) wit
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the set
1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packag
The Xiaomi router AX9000 has a post-authentication command injection vulnerability. This vulnerability is caused by the
A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers cou
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l
Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the prov
gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that t
TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker wit
An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prio
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenti
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affe
A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is
A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the functi
A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability i
A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFa
Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the
A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the functio
A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects
F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started