Command Injection (CWE-77)
CWE-77 covers products that build a command from externally influenced input without neutralizing special elements that can change the command once a downstream component receives it. It is a Class that covers command languages in general, operating system shells being just one of them. Many protocols and products define their own command syntax, and those can carry the same flaw.
About CWE-77
An injected delimiter can end the intended command and start a new one, which hands the attacker capabilities they would not otherwise hold. The listed scopes are integrity, confidentiality and availability.
Mitigations
- +Use library calls instead of launching external processes wherever the same function is available.
- +Build every external command statically so that no part of it comes from outside input.
- +Validate input against a strict allowlist of known-good values and reject anything that does not conform.
- +Enforce a run time policy that only permits sanctioned commands to execute.
- +Set permissions so that the process cannot open privileged files.
Detection
MITRE rates automated static analysis (SAST) as highly effective here, since data flow modeling can link input sources to command sinks.
CWE-77 Vulnerabilities
121 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-8037 | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF | Progress Software | 9.6 | 77.4% | KEV | 2026-06-04 |
| CVE-2026-42271 | LiteLLM: Authenticated command execution via MCP stdio test endpoints | BerriAI | 8.7 | 92.6% | KEV | 2026-05-08 |
| CVE-2025-4008 | Arbitrary Command Injection in Smartbedded MeteoBridge | Smartbedded | 8.7 | 93.7% | KEV | 2025-05-21 |
| CVE-2025-10035 | Deserialization Vulnerability in GoAnywhere MFT's License Servlet | Fortra | 10.0 | 99.8% | KEV | 2025-09-18 |
| CVE-2025-59689 | Libraesva Email Security Gateway Command Injection Vulnerability | Libraesva | 6.1 | 1.9% | KEV | 2025-09-19 |
| CVE-2024-12987 | DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection | DrayTek | 7.5 | 98.2% | KEV | 2024-12-27 |
| CVE-2024-12356 | Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA) | BeyondTrust | 9.8 | 87.3% | KEV | 2024-12-17 |
| CVE-2024-9380 | Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability | Ivanti | 7.2 | 59.7% | KEV | 2024-10-08 |
| CVE-2024-3400 | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect | Palo Alto Networks | 10.0 | 100.0% | KEV | 2024-04-12 |
| CVE-2024-3273 | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection | D-Link | 7.5 | 100.0% | KEV | 2024-04-04 |
| CVE-2018-19949 | QNAP NAS File Station Command Injection Vulnerability | QNAP Systems Inc. | 9.8 | 28.6% | KEV | 2020-10-28 |
| CVE-2020-2509 | Command Injection Vulnerability in QTS and QuTS hero | QNAP Systems Inc. | 9.8 | 34.0% | KEV | 2021-04-17 |
| CVE-2021-22899 | Ivanti Pulse Connect Secure Command Injection Vulnerability | - | 8.8 | 22.9% | KEV | 2021-05-27 |
| CVE-2026-2537 | Comfast CF-E4 HTTP POST Request mbox-config command injection | Comfast | 5.8 | 25.8% | 2026-02-16 | |
| CVE-2026-4197 | D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection | D-Link | 6.5 | 23.7% | 2026-03-15 | |
| CVE-2026-22755 | Legacy Vivotek Camera Firmware Command Injection in upload_map.cgi | Vivotek | 9.3 | 20.4% | 2026-01-13 | |
| CVE-2026-2000 | DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection | DCN | 5.8 | 19.7% | 2026-02-06 | |
| CVE-2026-2131 | XixianLiang HarmonyOS-mcp-server input_text os command injection | XixianLiang | 6.5 | 17.5% | 2026-02-08 | |
| CVE-2026-1419 | D-Link DCS700l Web Form setDayNightMode command injection | D-Link | 5.8 | 17.2% | 2026-01-26 | |
| CVE-2026-1125 | D-Link DIR-823X set_wifidog_settings sub_412E7C command injection | D-Link | 7.5 | 15.7% | 2026-01-18 | |
| CVE-2026-2535 | Comfast CF-N1 V2 mbox-config sub_44AB9C command injection | Comfast | 6.5 | 14.3% | 2026-02-16 | |
| CVE-2026-2534 | Comfast CF-N1 V2 mbox-config sub_44AC4C command injection | Comfast | 6.5 | 13.8% | 2026-02-16 | |
| CVE-2026-0732 | D-Link DI-8200G upgrade_filter.asp command injection | D-Link | 6.5 | 11.7% | 2026-01-08 | |
| CVE-2026-2823 | Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection | Comfast | 6.5 | 11.5% | 2026-02-20 | |
| CVE-2026-2824 | Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection | Comfast | 6.5 | 11.5% | 2026-02-20 | |
| CVE-2026-3661 | Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection | Wavlink | 5.8 | 11.3% | 2026-03-07 | |
| CVE-2026-3662 | Wavlink WL-NU516U1 adm.cgi usb_p910 command injection | Wavlink | 5.8 | 11.3% | 2026-03-07 | |
| CVE-2026-3798 | Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injection | Comfast | 5.8 | 11.3% | 2026-03-09 | |
| CVE-2026-2080 | UTT HiPER 810 formUser setSysAdm command injection | UTT | 8.6 | 10.8% | 2026-02-07 | |
| CVE-2026-2184 | Great Developers Certificate Generation System csv.php os command injection | Great Developers | 7.5 | 10.7% | 2026-02-08 | |
| CVE-2026-3612 | Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection | Wavlink | 8.6 | 10.4% | 2026-03-06 | |
| CVE-2026-5339 | Tenda G103 Setting gpon.lua action_set_net_settings command injection | Tenda | 5.8 | 10.2% | 2026-04-02 | |
| CVE-2026-7608 | TRENDnet TEW-821DAP tools_diagnostic os command injection | TRENDnet | 5.5 | 9.8% | 2026-05-02 | |
| CVE-2026-2182 | UTT 进取 521G setSysAdm doSystem command injection | UTT | 8.6 | 9.7% | 2026-02-08 | |
| CVE-2026-0581 | Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection | Tenda | 6.5 | 9.4% | 2026-01-05 | |
| CVE-2026-4228 | LB-LINK BL-WR9000 set_wifi sub_458754 command injection | LB-LINK | 6.5 | 8.9% | 2026-03-16 | |
| CVE-2026-5183 | TRENDnet TEW-713RE addRouting sub_421494 command injection | TRENDnet | 6.5 | 8.9% | 2026-03-31 | |
| CVE-2026-2956 | qinming99 dst-admin restore revertBackup command injection | qinming99 | 6.5 | 8.8% | 2026-02-22 | |
| CVE-2026-8263 | Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection | Tenda | 5.8 | 8.7% | 2026-05-11 | |
| CVE-2026-2527 | Wavlink WL-WN579A3 login.cgi command injection | Wavlink | 6.5 | 8.7% | 2026-02-16 | |
| CVE-2026-3064 | HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-3065 | HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-3066 | HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection | - | 6.5 | 8.6% | 2026-02-24 | |
| CVE-2026-5184 | TRENDnet TEW-713RE setSysAdm command injection | TRENDnet | 6.5 | 8.5% | 2026-03-31 | |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-2528 | Wavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-2526 | Wavlink WL-WN579A3 wireless.cgi multi_ssid command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-2530 | Wavlink WL-WN579A3 wireless.cgi AddMac command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-5338 | Tenda G103 Setting system.lua action_set_system_settings command injection | Tenda | 5.8 | 8.3% | 2026-04-02 | |
| CVE-2026-8259 | Tenda AC6 httpd telnet os command injection | Tenda | 5.8 | 8.3% | 2026-05-11 | |
| CVE-2026-8265 | Tenda AC6 httpd getLogFile get_log_file os command injection | Tenda | 5.8 | 8.3% | 2026-05-11 | |
| CVE-2026-4253 | Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection | Tenda | 5.8 | 8.2% | 2026-03-16 | |
| CVE-2026-2615 | Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection | Wavlink | 8.6 | 8.0% | 2026-02-17 | |
| CVE-2026-6992 | Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection | Linksys | 8.6 | 8.0% | 2026-04-25 | |
| CVE-2026-46368 | luci-app-https-dns-proxy Authenticated Command Injection via setInitAction | mossdef-org | 8.8 | 7.8% | 2026-05-26 | |
| CVE-2026-4558 | Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection | Linksys | 9.0 | 7.8% | 2026-03-22 | |
| CVE-2026-2846 | UTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection | UTT | 8.6 | 7.5% | 2026-02-20 | |
| CVE-2026-2847 | UTT HiPER 520 Web Management formReleaseConnect sub_44EFB4 os command injection | UTT | 8.6 | 7.5% | 2026-02-20 | |
| CVE-2026-2944 | Tosei Online Store Management System ネット店舗管理システム HTTP POST Request monitor.php system os command injection | Tosei | 7.5 | 7.3% | 2026-02-22 | |
| CVE-2026-2952 | Vaelsys HTTP POST Request tree_server.php os command injection | - | 7.5 | 7.3% | 2026-02-22 | |
| CVE-2026-2188 | UTT 进取 521G formPdbUpConfig sub_446B18 os command injection | UTT | 8.6 | 7.2% | 2026-02-08 | |
| CVE-2026-3040 | DrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection | DrayTek | 5.8 | 7.2% | 2026-02-23 | |
| CVE-2026-1324 | Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection | Sangfor | 9.0 | 7.1% | 2026-01-22 | |
| CVE-2026-8767 | vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection | vercel | 5.0 | 7.0% | 2026-05-17 | |
| CVE-2026-1192 | Tosei Online Store Management System ネット店舗管理システム imode_alldata.php command injection | Tosei | 7.5 | 6.9% | 2026-01-19 | |
| CVE-2026-2227 | D-Link DCS-931L setSystemAdmin doSystem command injection | D-Link | 5.8 | 6.8% | 2026-02-09 | |
| CVE-2026-3485 | D-Link DIR-868L SSDP Service sub_1BF84 os command injection | D-Link | 10.0 | 6.7% | 2026-03-03 | |
| CVE-2026-2142 | D-Link DIR-823X set_qos sub_420688 os command injection | D-Link | 8.6 | 6.6% | 2026-02-08 | |
| CVE-2026-2163 | D-Link DIR-600 ssdp.cgi command injection | D-Link | 5.8 | 6.6% | 2026-02-08 | |
| CVE-2026-3101 | Intelbras TIP 635G Ping os command injection | Intelbras | 6.5 | 6.6% | 2026-02-24 | |
| CVE-2026-4554 | Tenda F453 WriteFacMac FormWriteFacMac privilege escalation | Tenda | 6.5 | 6.5% | 2026-03-22 | |
| CVE-2026-5153 | Tenda CH22 WriteFacMac FormWriteFacMac command injection | Tenda | 6.5 | 6.5% | 2026-03-30 | |
| CVE-2026-7102 | Tenda F456 httpd WriteFacMac FromWriteFacMac command injection | Tenda | 6.5 | 6.5% | 2026-04-27 | |
| CVE-2026-8264 | Tenda AC6 httpd WifiApScan formWifiApScan os command injection | Tenda | 6.5 | 6.5% | 2026-05-11 | |
| CVE-2026-2081 | D-Link DIR-823X set_password os command injection | D-Link | 5.8 | 6.4% | 2026-02-07 | |
| CVE-2026-6989 | Tenda F453 Telnet Service telnet TendaTelnet command injection | Tenda | 6.5 | 6.3% | 2026-04-25 | |
| CVE-2026-5844 | D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection | D-Link | 8.6 | 6.2% | 2026-04-09 | |
| CVE-2026-4203 | D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection | D-Link | 6.5 | 6.1% | 2026-03-16 | |
| CVE-2026-8271 | D-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection | D-Link | 5.8 | 6.1% | 2026-05-11 | |
| CVE-2026-8272 | D-Link DNS-320 webfile_mgr.cgi chown os command injection | D-Link | 5.8 | 6.0% | 2026-05-11 | |
| CVE-2026-7690 | Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection | Wavlink | 6.5 | 6.0% | 2026-05-03 | |
| CVE-2026-2082 | D-Link DIR-823X set_mac_clone os command injection | D-Link | 5.8 | 5.9% | 2026-02-07 | |
| CVE-2026-2260 | D-Link DCS-931L setSysAdmin os command injection | D-Link | 8.6 | 5.8% | 2026-02-10 | |
| CVE-2026-1448 | D-Link DIR-615 Web Management wiz_policy_3_machine.php os command injection | D-Link | 8.6 | 5.8% | 2026-01-26 | |
| CVE-2026-4209 | D-Link DNS-1550-04 account_mgr.cgi cgi_chg_admin_pw command injection | D-Link | 6.5 | 5.8% | 2026-03-16 | |
| CVE-2026-4196 | D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection | D-Link | 6.5 | 5.8% | 2026-03-15 | |
| CVE-2026-4207 | D-Link DNS-1550-04 system_mgr.cgi cgi_ntp_time command injection | D-Link | 6.5 | 5.8% | 2026-03-16 | |
| CVE-2026-5351 | Trendnet TEW-657BRM setup.cgi add_wps_client os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5352 | Trendnet TEW-657BRM setup.cgi edit os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5353 | Trendnet TEW-657BRM setup.cgi ping_test os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5354 | Trendnet TEW-657BRM setup.cgi vpn_connect os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5355 | Trendnet TEW-657BRM setup.cgi vpn_drop os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-7609 | TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection | TRENDnet | 6.5 | 5.7% | 2026-05-02 | |
| CVE-2026-4585 | Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection | Tiandy | 10.0 | 5.7% | 2026-03-23 | |
| CVE-2026-1506 | D-Link DIR-615 MAC Filter Configuration adv_mac_filter.php os command injection | D-Link | 8.6 | 5.6% | 2026-01-28 | |
| CVE-2026-1066 | kalcaddle kodbox Compression zip command injection | kalcaddle | 6.5 | 5.6% | 2026-01-17 | |
| CVE-2026-13545 | D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection | D-Link | 9.0 | 5.5% | 2026-06-29 | |
| CVE-2026-3704 | Wavlink NU516U1 Incomplete Fix CVE-2025-10959 firewall.cgi sub_405B2C command injection | Wavlink | 5.8 | 5.5% | 2026-03-08 | |
| CVE-2026-4195 | D-Link DNS-1550-04 wizard_mgr.cgi command injection | D-Link | 6.5 | 5.5% | 2026-03-15 | |
| CVE-2026-4204 | D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection | D-Link | 6.5 | 5.5% | 2026-03-16 | |
| CVE-2026-4210 | D-Link DNS-1550-04 time_machine.cgi cgi_tm_set_share command injection | D-Link | 6.5 | 5.5% | 2026-03-16 | |
| CVE-2026-2152 | D-Link DIR-615 Web Configuration adv_routing.php os command injection | D-Link | 8.6 | 5.4% | 2026-02-08 | |
| CVE-2026-2151 | D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection | D-Link | 8.6 | 5.3% | 2026-02-08 | |
| CVE-2026-2063 | D-Link DIR-823X Web Management set_ac_server os command injection | D-Link | 5.8 | 5.3% | 2026-02-06 | |
| CVE-2026-2085 | D-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection | D-Link | 8.6 | 5.2% | 2026-02-07 | |
| CVE-2026-2061 | D-Link DIR-823X set_ipv6 sub_424D20 os command injection | D-Link | 5.8 | 5.1% | 2026-02-06 | |
| CVE-2026-4205 | D-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection | D-Link | 6.5 | 5.1% | 2026-03-16 | |
| CVE-2026-4206 | D-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection | D-Link | 6.5 | 5.1% | 2026-03-16 | |
| CVE-2026-1505 | D-Link DIR-615 URL Filter set_temp_nodes.php os command injection | D-Link | 8.6 | 5.1% | 2026-01-28 | |
| CVE-2026-2129 | D-Link DIR-823X set_ac_status os command injection | D-Link | 8.6 | 5.0% | 2026-02-08 | |
| CVE-2026-2143 | D-Link DIR-823X DDNS Service set_ddns os command injection | D-Link | 8.6 | 5.0% | 2026-02-08 | |
| CVE-2026-10060 | TRENDnet TEW-432BRP formSetRoute command injection | TRENDnet | 6.5 | 5.0% | 2026-05-29 | |
| CVE-2026-10061 | TRENDnet TEW-432BRP formWPS command injection | TRENDnet | 6.5 | 5.0% | 2026-05-29 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-77?→
CWE-77 is the MITRE class for command injection in any command language. The product assembles a command from outside input and fails to neutralize elements that alter its meaning.
Should CWE-77 or CWE-78 be used for shell command injection?→
MITRE notes that CWE-77 is often misused when OS command injection (CWE-78) was meant. CWE-78 fits shell invocation, while CWE-77 suits other command languages.
How many exploited vulnerabilities are classified as CWE-77?→
This database lists 121 CVE records mapped to CWE-77 by their CVE Numbering Authority. 13 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-8037, CVE-2026-42271, CVE-2025-4008.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.