CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an att
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use t
In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and ex
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote att
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an ad
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrar
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrar
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an
IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Fo
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue
ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command
Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change a
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6000 before 1.0.0.75,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.48,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6100 before 1.0.0.63,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.10.2
NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.15.25
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.15.25
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.40,
A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticate
A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (I
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38,
Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitra
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a craft
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers c
In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manuall
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58,
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started