CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Sto
LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface
TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in
Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obt
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execut
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.late
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported functi
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, th
This affects all versions of package monorepo-build.
This affects the package image-tiler before 2.0.2.
D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V1
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, whic
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/up
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /w
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 an
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddr
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping par
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.
Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as
An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettin
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of speci
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes ar
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in us
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Ma
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTrigg
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious act
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute a
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_rest
Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifu
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started