CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component W
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interf
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connec
A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unk
MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attack
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gain
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gain
A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allo
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh
Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2C
A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver
An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5.
An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0
An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5
Local user may lead to privilege escalation using Gaia Portal hostnames page.
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an au
A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authent
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to
TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerabilit
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of
Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoin
In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on t
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative right
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administ
jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filteri
Windows MSHTML Platform Security Feature Bypass Vulnerability
An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1
ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 3
Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection ob
A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to
There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_D
The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware vers
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started