CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command exe
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mi
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects EX6200v2 before 1
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects XR300 before 1.0.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK20 before 2.6.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Imprope
A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for co
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a
A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows re
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an admini
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly hand
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vuln
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers fo
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started