Skip to main content

About CWE-74

Consequences listed by MITRE include disclosure of application data, bypass of authentication, altered execution logic, loss of data integrity and unlogged activity.

MITRE marks CWE-74 as DISCOURAGED for mapping real-world vulnerabilities because it is high-level and often misused; examine its children for a better fit.

MITRE name
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Incomplete

Mitigations

  • +Choose programming languages and supporting technologies that are not subject to these parsing issues.
  • +Combine allowlist and denylist parsing to filter control-plane syntax out of all input.
  • +Map each finding to a more specific child entry such as SQL injection or OS command injection, which carry targeted mitigations.

Detection
Automated static analysis (SAST) is rated highly effective, using data flow and control flow models to connect input sources with sinks.

CWE-74 Vulnerabilities

56 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2022-43769
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
Hitachi Vantara8.897.7%KEV2023-04-03
CVE-2022-46169
Unauthenticated Command Injection
Cacti9.899.8%KEV2022-12-05
CVE-2026-22200
osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read
Enhancesoft8.773.6%2026-01-12
CVE-2026-2537
Comfast CF-E4 HTTP POST Request mbox-config command injection
Comfast5.825.8%2026-02-16
CVE-2026-4197
D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection
D-Link6.523.7%2026-03-15
CVE-2026-2000
DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection
DCN5.819.7%2026-02-06
CVE-2026-1419
D-Link DCS700l Web Form setDayNightMode command injection
D-Link5.817.2%2026-01-26
CVE-2026-1125
D-Link DIR-823X set_wifidog_settings sub_412E7C command injection
D-Link7.515.7%2026-01-18
CVE-2026-2535
Comfast CF-N1 V2 mbox-config sub_44AB9C command injection
Comfast6.514.3%2026-02-16
CVE-2026-2534
Comfast CF-N1 V2 mbox-config sub_44AC4C command injection
Comfast6.513.8%2026-02-16
CVE-2026-0732
D-Link DI-8200G upgrade_filter.asp command injection
D-Link6.511.7%2026-01-08
CVE-2026-2823
Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection
Comfast6.511.5%2026-02-20
CVE-2026-2824
Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection
Comfast6.511.5%2026-02-20
CVE-2026-3661
Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection
Wavlink5.811.3%2026-03-07
CVE-2026-3662
Wavlink WL-NU516U1 adm.cgi usb_p910 command injection
Wavlink5.811.3%2026-03-07
CVE-2026-3798
Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injection
Comfast5.811.3%2026-03-09
CVE-2026-2080
UTT HiPER 810 formUser setSysAdm command injection
UTT8.610.8%2026-02-07
CVE-2026-3612
Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection
Wavlink8.610.4%2026-03-06
CVE-2026-5339
Tenda G103 Setting gpon.lua action_set_net_settings command injection
Tenda5.810.2%2026-04-02
CVE-2026-2182
UTT 进取 521G setSysAdm doSystem command injection
UTT8.69.7%2026-02-08
CVE-2026-0581
Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection
Tenda6.59.4%2026-01-05
CVE-2026-4228
LB-LINK BL-WR9000 set_wifi sub_458754 command injection
LB-LINK6.58.9%2026-03-16
CVE-2026-5183
TRENDnet TEW-713RE addRouting sub_421494 command injection
TRENDnet6.58.9%2026-03-31
CVE-2026-2956
qinming99 dst-admin restore revertBackup command injection
qinming996.58.8%2026-02-22
CVE-2026-2527
Wavlink WL-WN579A3 login.cgi command injection
Wavlink6.58.7%2026-02-16
CVE-2026-3064
HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection
-6.58.6%2026-02-24
CVE-2026-3065
HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult command injection
-6.58.6%2026-02-24
CVE-2026-3066
HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection
-6.58.6%2026-02-24
CVE-2026-5184
TRENDnet TEW-713RE setSysAdm command injection
TRENDnet6.58.5%2026-03-31
CVE-2026-2528
Wavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection
Wavlink6.58.4%2026-02-16
CVE-2026-2526
Wavlink WL-WN579A3 wireless.cgi multi_ssid command injection
Wavlink6.58.4%2026-02-16
CVE-2026-2530
Wavlink WL-WN579A3 wireless.cgi AddMac command injection
Wavlink6.58.4%2026-02-16
CVE-2026-5338
Tenda G103 Setting system.lua action_set_system_settings command injection
Tenda5.88.3%2026-04-02
CVE-2026-2615
Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection
Wavlink8.68.0%2026-02-17
CVE-2026-1192
Tosei Online Store Management System ネット店舗管理システム imode_alldata.php command injection
Tosei7.56.9%2026-01-19
CVE-2026-2227
D-Link DCS-931L setSystemAdmin doSystem command injection
D-Link5.86.8%2026-02-09
CVE-2026-2163
D-Link DIR-600 ssdp.cgi command injection
D-Link5.86.6%2026-02-08
CVE-2026-4554
Tenda F453 WriteFacMac FormWriteFacMac privilege escalation
Tenda6.56.5%2026-03-22
CVE-2026-5153
Tenda CH22 WriteFacMac FormWriteFacMac command injection
Tenda6.56.5%2026-03-30
CVE-2026-7102
Tenda F456 httpd WriteFacMac FromWriteFacMac command injection
Tenda6.56.5%2026-04-27
CVE-2026-6989
Tenda F453 Telnet Service telnet TendaTelnet command injection
Tenda6.56.3%2026-04-25
CVE-2026-4203
D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection
D-Link6.56.1%2026-03-16
CVE-2026-7690
Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection
Wavlink6.56.0%2026-05-03
CVE-2026-4209
D-Link DNS-1550-04 account_mgr.cgi cgi_chg_admin_pw command injection
D-Link6.55.8%2026-03-16
CVE-2026-4196
D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection
D-Link6.55.8%2026-03-15
CVE-2026-4207
D-Link DNS-1550-04 system_mgr.cgi cgi_ntp_time command injection
D-Link6.55.8%2026-03-16
CVE-2026-1066
kalcaddle kodbox Compression zip command injection
kalcaddle6.55.6%2026-01-17
CVE-2026-3704
Wavlink NU516U1 Incomplete Fix CVE-2025-10959 firewall.cgi sub_405B2C command injection
Wavlink5.85.5%2026-03-08
CVE-2026-4195
D-Link DNS-1550-04 wizard_mgr.cgi command injection
D-Link6.55.5%2026-03-15
CVE-2026-4204
D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection
D-Link6.55.5%2026-03-16
CVE-2026-4210
D-Link DNS-1550-04 time_machine.cgi cgi_tm_set_share command injection
D-Link6.55.5%2026-03-16
CVE-2026-2085
D-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection
D-Link8.65.2%2026-02-07
CVE-2026-4205
D-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection
D-Link6.55.1%2026-03-16
CVE-2026-4206
D-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection
D-Link6.55.1%2026-03-16
CVE-2026-10060
TRENDnet TEW-432BRP formSetRoute command injection
TRENDnet6.55.0%2026-05-29
CVE-2026-10061
TRENDnet TEW-432BRP formWPS command injection
TRENDnet6.55.0%2026-05-29

Frequently Asked Questions

What does CWE-74 cover?→

CWE-74 is the parent Class for injection weaknesses, where outside input changes how a downstream component interprets output. SQL injection, OS command injection and cross-site scripting sit beneath it.

Can CWE-74 be used to classify a CVE?→

MITRE marks CWE-74 as discouraged for vulnerability mapping because of its high abstraction and frequent misuse. Its children and descendants are the recommended targets.

How many exploited vulnerabilities are classified as CWE-74?→

This database lists 56 CVE records mapped to CWE-74 by their CVE Numbering Authority. 2 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2022-43769, CVE-2022-46169, CVE-2026-22200.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.