CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execu
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2
Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspe
We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and U
FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain paramete
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to
This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marve
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.c
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h
node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10,
NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBS40V before 2.6.1.4,
The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the applica
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7500v2 before 1.0.3.48
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 a
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 a
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,
NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.
In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted she
A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbi
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 a
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitr
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to a
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalatio
A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstr
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started