CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions p
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before versio
It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4
In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Act
IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlie
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can ex
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of pro
A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the
Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.
The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the conte
A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ver
An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi-bin/script query strin
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the if
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-6
On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the p
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi scrip
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vuln
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB fold
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB fold
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) al
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful expl
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, lead
A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthentica
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fi
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix
Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitra
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variabl
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafte
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command inject
There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI h
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute a
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attacker
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attac
An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH
A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started