CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in ma
includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a mali
A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default ce
VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail
A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cach
A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects EX6120 before 1.0.0.66,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.3.106
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX75 before 1.0.3.106,
Certain NETGEAR devices are affected by command injection by an authenticated user . This affects RAX200 before 1.0.3.10
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX75 before 1.0.3.106,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900 before 1.0.4.38,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R8000 before 1.0.4.74,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.74,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started