CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub
The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server ar
LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection.
Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could l
The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to ach
NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on t
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Spe
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie
Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pas
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command
rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbr
emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection v
This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affec
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arb
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execut
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has alre
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issu
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a r
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject an
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allo
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (usin
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Ar
Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command executio
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrar
Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote a
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command usin
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an aut
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c
iCatch DVR firmware before 20200103 do not validate function parameter properly, resulting attackers executing arbitrary
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52,
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started