Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 67/74
7.5
CVE-2020-4432

Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an att

7.4
CVE-2019-14868

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use t

7.3
CVE-2020-4059

In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a

7.3
CVE-2020-26929

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100

7.2
CVE-2019-12629

A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and ex

7.2
CVE-2019-16005

A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote att

7.2
CVE-2019-5323

There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an ad

7.2
CVE-2019-20659

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84

7.2
CVE-2020-3211

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrar

7.2
CVE-2020-3212

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrar

7.2
CVE-2020-3274

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3275

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3276

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3277

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3278

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-3279

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers an

7.2
CVE-2020-4636

IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Fo

7.2
CVE-2020-2490

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue

7.2
CVE-2020-2492

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue

7.2
CVE-2020-9115

ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command

7.2
CVE-2020-9116

Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker

7.2
CVE-2020-29299

Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change a

7.0
CVE-2020-7384

Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish

6.8
CVE-2019-20688

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75,

6.8
CVE-2019-20689

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6000 before 1.0.0.75,

6.8
CVE-2019-20718

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.48,

6.8
CVE-2019-20722

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44,

6.8
CVE-2019-20724

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75,

6.8
CVE-2019-20726

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75,

6.8
CVE-2019-20727

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6100 before 1.0.0.63,

6.8
CVE-2019-20745

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.10.2

6.8
CVE-2019-20757

NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.

6.8
CVE-2020-14433

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.15.25

6.8
CVE-2020-14434

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.15.25

6.8
CVE-2020-9199

B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with

6.7
CVE-2020-3176

A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on

6.7
CVE-2019-20651

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16

6.7
CVE-2019-20732

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.40,

6.7
CVE-2020-3207

A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticate

6.7
CVE-2020-3210

A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (I

6.7
CVE-2020-26914

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38,

6.7
CVE-2020-11496

Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitra

6.7
CVE-2020-9127

Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high

6.5
CVE-2019-12921

In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a craft

6.4
CVE-2020-3924

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers c

6.4
CVE-2020-11084

In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manuall

6.4
CVE-2020-26922

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24,

6.4
CVE-2020-35790

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56,

6.4
CVE-2020-35791

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68,

6.1
CVE-2020-35793

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58,

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started