CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBR20 before 2.7.3.22,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBS50Y before 2.7.3.22,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR750 before 4.6.3.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR750 before 4.6.3.6,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24,
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R7800 before 1.0.
Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer
Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users t
An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send
An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiri
An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send
An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Se
An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock<T> unconditionally implements Send and Syn
An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds o
An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for a
An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds
An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations o
An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send fo
An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline com
Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Sett
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit
The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontr
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable
Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security perm
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unpri
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started