Skip to main content

About CWE-77

An injected delimiter can end the intended command and start a new one, which hands the attacker capabilities they would not otherwise hold. The listed scopes are integrity, confidentiality and availability.

MITRE name
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Draft
Also known as
Command injection

Mitigations

  • +Use library calls instead of launching external processes wherever the same function is available.
  • +Build every external command statically so that no part of it comes from outside input.
  • +Validate input against a strict allowlist of known-good values and reject anything that does not conform.
  • +Enforce a run time policy that only permits sanctioned commands to execute.
  • +Set permissions so that the process cannot open privileged files.

Detection
MITRE rates automated static analysis (SAST) as highly effective here, since data flow modeling can link input sources to command sinks.

CWE-77 Vulnerabilities

121 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Progress Software9.677.4%KEV2026-06-04
CVE-2026-42271
LiteLLM: Authenticated command execution via MCP stdio test endpoints
BerriAI8.792.6%KEV2026-05-08
CVE-2025-4008
Arbitrary Command Injection in Smartbedded MeteoBridge
Smartbedded8.793.7%KEV2025-05-21
CVE-2025-10035
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
Fortra10.099.8%KEV2025-09-18
CVE-2025-59689
Libraesva Email Security Gateway Command Injection Vulnerability
Libraesva6.11.9%KEV2025-09-19
CVE-2024-12987
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
DrayTek7.598.2%KEV2024-12-27
CVE-2024-12356
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
BeyondTrust9.887.3%KEV2024-12-17
CVE-2024-9380
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
Ivanti7.259.7%KEV2024-10-08
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
Palo Alto Networks10.0100.0%KEV2024-04-12
CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
D-Link7.5100.0%KEV2024-04-04
CVE-2018-19949
QNAP NAS File Station Command Injection Vulnerability
QNAP Systems Inc.9.828.6%KEV2020-10-28
CVE-2020-2509
Command Injection Vulnerability in QTS and QuTS hero
QNAP Systems Inc.9.834.0%KEV2021-04-17
CVE-2021-22899
Ivanti Pulse Connect Secure Command Injection Vulnerability
-8.822.9%KEV2021-05-27
CVE-2026-2537
Comfast CF-E4 HTTP POST Request mbox-config command injection
Comfast5.825.8%2026-02-16
CVE-2026-4197
D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection
D-Link6.523.7%2026-03-15
CVE-2026-22755
Legacy Vivotek Camera Firmware Command Injection in upload_map.cgi
Vivotek9.320.4%2026-01-13
CVE-2026-2000
DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection
DCN5.819.7%2026-02-06
CVE-2026-2131
XixianLiang HarmonyOS-mcp-server input_text os command injection
XixianLiang6.517.5%2026-02-08
CVE-2026-1419
D-Link DCS700l Web Form setDayNightMode command injection
D-Link5.817.2%2026-01-26
CVE-2026-1125
D-Link DIR-823X set_wifidog_settings sub_412E7C command injection
D-Link7.515.7%2026-01-18
CVE-2026-2535
Comfast CF-N1 V2 mbox-config sub_44AB9C command injection
Comfast6.514.3%2026-02-16
CVE-2026-2534
Comfast CF-N1 V2 mbox-config sub_44AC4C command injection
Comfast6.513.8%2026-02-16
CVE-2026-0732
D-Link DI-8200G upgrade_filter.asp command injection
D-Link6.511.7%2026-01-08
CVE-2026-2823
Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection
Comfast6.511.5%2026-02-20
CVE-2026-2824
Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection
Comfast6.511.5%2026-02-20
CVE-2026-3661
Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection
Wavlink5.811.3%2026-03-07
CVE-2026-3662
Wavlink WL-NU516U1 adm.cgi usb_p910 command injection
Wavlink5.811.3%2026-03-07
CVE-2026-3798
Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injection
Comfast5.811.3%2026-03-09
CVE-2026-2080
UTT HiPER 810 formUser setSysAdm command injection
UTT8.610.8%2026-02-07
CVE-2026-2184
Great Developers Certificate Generation System csv.php os command injection
Great Developers7.510.7%2026-02-08
CVE-2026-3612
Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection
Wavlink8.610.4%2026-03-06
CVE-2026-5339
Tenda G103 Setting gpon.lua action_set_net_settings command injection
Tenda5.810.2%2026-04-02
CVE-2026-7608
TRENDnet TEW-821DAP tools_diagnostic os command injection
TRENDnet5.59.8%2026-05-02
CVE-2026-2182
UTT 进取 521G setSysAdm doSystem command injection
UTT8.69.7%2026-02-08
CVE-2026-0581
Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection
Tenda6.59.4%2026-01-05
CVE-2026-4228
LB-LINK BL-WR9000 set_wifi sub_458754 command injection
LB-LINK6.58.9%2026-03-16
CVE-2026-5183
TRENDnet TEW-713RE addRouting sub_421494 command injection
TRENDnet6.58.9%2026-03-31
CVE-2026-2956
qinming99 dst-admin restore revertBackup command injection
qinming996.58.8%2026-02-22
CVE-2026-8263
Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection
Tenda5.88.7%2026-05-11
CVE-2026-2527
Wavlink WL-WN579A3 login.cgi command injection
Wavlink6.58.7%2026-02-16
CVE-2026-3064
HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection
-6.58.6%2026-02-24
CVE-2026-3065
HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult command injection
-6.58.6%2026-02-24
CVE-2026-3066
HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection
-6.58.6%2026-02-24
CVE-2026-5184
TRENDnet TEW-713RE setSysAdm command injection
TRENDnet6.58.5%2026-03-31
CVE-2026-8188
Wavlink NU516U1 adm.cgi change_wifi_password os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8189
Wavlink NU516U1 adm.cgi wzdrepeater os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8190
Wavlink NU516U1 adm.cgi wan os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8191
Wavlink NU516U1 adm.cgi wifi_region os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8192
Wavlink NU516U1 adm.cgi wzdap os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8227
Wavlink NU516U1 adm.cgi wzdapMesh os command injection
Wavlink6.58.5%2026-05-10
CVE-2026-8228
Wavlink NU516U1 wireless.cgi advance os command injection
Wavlink6.58.5%2026-05-10
CVE-2026-8229
Wavlink NU516U1 wireless.cgi WifiBasic os command injection
Wavlink6.58.5%2026-05-10
CVE-2026-8230
Wavlink NU516U1 login.cgi sys_login1 os command injection
Wavlink6.58.5%2026-05-10
CVE-2026-2528
Wavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection
Wavlink6.58.4%2026-02-16
CVE-2026-2526
Wavlink WL-WN579A3 wireless.cgi multi_ssid command injection
Wavlink6.58.4%2026-02-16
CVE-2026-2530
Wavlink WL-WN579A3 wireless.cgi AddMac command injection
Wavlink6.58.4%2026-02-16
CVE-2026-5338
Tenda G103 Setting system.lua action_set_system_settings command injection
Tenda5.88.3%2026-04-02
CVE-2026-8259
Tenda AC6 httpd telnet os command injection
Tenda5.88.3%2026-05-11
CVE-2026-8265
Tenda AC6 httpd getLogFile get_log_file os command injection
Tenda5.88.3%2026-05-11
CVE-2026-4253
Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection
Tenda5.88.2%2026-03-16
CVE-2026-2615
Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection
Wavlink8.68.0%2026-02-17
CVE-2026-6992
Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection
Linksys8.68.0%2026-04-25
CVE-2026-46368
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
mossdef-org8.87.8%2026-05-26
CVE-2026-4558
Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection
Linksys9.07.8%2026-03-22
CVE-2026-2846
UTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection
UTT8.67.5%2026-02-20
CVE-2026-2847
UTT HiPER 520 Web Management formReleaseConnect sub_44EFB4 os command injection
UTT8.67.5%2026-02-20
CVE-2026-2944
Tosei Online Store Management System ネット店舗管理システム HTTP POST Request monitor.php system os command injection
Tosei7.57.3%2026-02-22
CVE-2026-2952
Vaelsys HTTP POST Request tree_server.php os command injection
-7.57.3%2026-02-22
CVE-2026-2188
UTT 进取 521G formPdbUpConfig sub_446B18 os command injection
UTT8.67.2%2026-02-08
CVE-2026-3040
DrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection
DrayTek5.87.2%2026-02-23
CVE-2026-1324
Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection
Sangfor9.07.1%2026-01-22
CVE-2026-8767
vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection
vercel5.07.0%2026-05-17
CVE-2026-1192
Tosei Online Store Management System ネット店舗管理システム imode_alldata.php command injection
Tosei7.56.9%2026-01-19
CVE-2026-2227
D-Link DCS-931L setSystemAdmin doSystem command injection
D-Link5.86.8%2026-02-09
CVE-2026-3485
D-Link DIR-868L SSDP Service sub_1BF84 os command injection
D-Link10.06.7%2026-03-03
CVE-2026-2142
D-Link DIR-823X set_qos sub_420688 os command injection
D-Link8.66.6%2026-02-08
CVE-2026-2163
D-Link DIR-600 ssdp.cgi command injection
D-Link5.86.6%2026-02-08
CVE-2026-3101
Intelbras TIP 635G Ping os command injection
Intelbras6.56.6%2026-02-24
CVE-2026-4554
Tenda F453 WriteFacMac FormWriteFacMac privilege escalation
Tenda6.56.5%2026-03-22
CVE-2026-5153
Tenda CH22 WriteFacMac FormWriteFacMac command injection
Tenda6.56.5%2026-03-30
CVE-2026-7102
Tenda F456 httpd WriteFacMac FromWriteFacMac command injection
Tenda6.56.5%2026-04-27
CVE-2026-8264
Tenda AC6 httpd WifiApScan formWifiApScan os command injection
Tenda6.56.5%2026-05-11
CVE-2026-2081
D-Link DIR-823X set_password os command injection
D-Link5.86.4%2026-02-07
CVE-2026-6989
Tenda F453 Telnet Service telnet TendaTelnet command injection
Tenda6.56.3%2026-04-25
CVE-2026-5844
D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection
D-Link8.66.2%2026-04-09
CVE-2026-4203
D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection
D-Link6.56.1%2026-03-16
CVE-2026-8271
D-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection
D-Link5.86.1%2026-05-11
CVE-2026-8272
D-Link DNS-320 webfile_mgr.cgi chown os command injection
D-Link5.86.0%2026-05-11
CVE-2026-7690
Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection
Wavlink6.56.0%2026-05-03
CVE-2026-2082
D-Link DIR-823X set_mac_clone os command injection
D-Link5.85.9%2026-02-07
CVE-2026-2260
D-Link DCS-931L setSysAdmin os command injection
D-Link8.65.8%2026-02-10
CVE-2026-1448
D-Link DIR-615 Web Management wiz_policy_3_machine.php os command injection
D-Link8.65.8%2026-01-26
CVE-2026-4209
D-Link DNS-1550-04 account_mgr.cgi cgi_chg_admin_pw command injection
D-Link6.55.8%2026-03-16
CVE-2026-4196
D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection
D-Link6.55.8%2026-03-15
CVE-2026-4207
D-Link DNS-1550-04 system_mgr.cgi cgi_ntp_time command injection
D-Link6.55.8%2026-03-16
CVE-2026-5351
Trendnet TEW-657BRM setup.cgi add_wps_client os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-5352
Trendnet TEW-657BRM setup.cgi edit os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-5353
Trendnet TEW-657BRM setup.cgi ping_test os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-5354
Trendnet TEW-657BRM setup.cgi vpn_connect os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-5355
Trendnet TEW-657BRM setup.cgi vpn_drop os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-7609
TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection
TRENDnet6.55.7%2026-05-02
CVE-2026-4585
Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection
Tiandy10.05.7%2026-03-23
CVE-2026-1506
D-Link DIR-615 MAC Filter Configuration adv_mac_filter.php os command injection
D-Link8.65.6%2026-01-28
CVE-2026-1066
kalcaddle kodbox Compression zip command injection
kalcaddle6.55.6%2026-01-17
CVE-2026-13545
D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
D-Link9.05.5%2026-06-29
CVE-2026-3704
Wavlink NU516U1 Incomplete Fix CVE-2025-10959 firewall.cgi sub_405B2C command injection
Wavlink5.85.5%2026-03-08
CVE-2026-4195
D-Link DNS-1550-04 wizard_mgr.cgi command injection
D-Link6.55.5%2026-03-15
CVE-2026-4204
D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection
D-Link6.55.5%2026-03-16
CVE-2026-4210
D-Link DNS-1550-04 time_machine.cgi cgi_tm_set_share command injection
D-Link6.55.5%2026-03-16
CVE-2026-2152
D-Link DIR-615 Web Configuration adv_routing.php os command injection
D-Link8.65.4%2026-02-08
CVE-2026-2151
D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection
D-Link8.65.3%2026-02-08
CVE-2026-2063
D-Link DIR-823X Web Management set_ac_server os command injection
D-Link5.85.3%2026-02-06
CVE-2026-2085
D-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection
D-Link8.65.2%2026-02-07
CVE-2026-2061
D-Link DIR-823X set_ipv6 sub_424D20 os command injection
D-Link5.85.1%2026-02-06
CVE-2026-4205
D-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection
D-Link6.55.1%2026-03-16
CVE-2026-4206
D-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection
D-Link6.55.1%2026-03-16
CVE-2026-1505
D-Link DIR-615 URL Filter set_temp_nodes.php os command injection
D-Link8.65.1%2026-01-28
CVE-2026-2129
D-Link DIR-823X set_ac_status os command injection
D-Link8.65.0%2026-02-08
CVE-2026-2143
D-Link DIR-823X DDNS Service set_ddns os command injection
D-Link8.65.0%2026-02-08
CVE-2026-10060
TRENDnet TEW-432BRP formSetRoute command injection
TRENDnet6.55.0%2026-05-29
CVE-2026-10061
TRENDnet TEW-432BRP formWPS command injection
TRENDnet6.55.0%2026-05-29

Frequently Asked Questions

What is CWE-77?→

CWE-77 is the MITRE class for command injection in any command language. The product assembles a command from outside input and fails to neutralize elements that alter its meaning.

Should CWE-77 or CWE-78 be used for shell command injection?→

MITRE notes that CWE-77 is often misused when OS command injection (CWE-78) was meant. CWE-78 fits shell invocation, while CWE-77 suits other command languages.

How many exploited vulnerabilities are classified as CWE-77?→

This database lists 121 CVE records mapped to CWE-77 by their CVE Numbering Authority. 13 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-8037, CVE-2026-42271, CVE-2025-4008.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.