CWE-78
6,663 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,663)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the restart_modules in file /usr/lib/lua/luci/controller/admin/common.lua. |
1Ruijie 2Rg Eap602 Firmware Rg Ew1200g Pro FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_...Show more |
1Ruijie 2Rg Ew300 Pro Firmware X30 Pro FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/host_access_delay.lua. |
1Ruijie 3Rg Eap602 Firmware Rg Ew300 Pro FirmwareX30 Pro FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless.lua. |
1Ruijie 2Rg Ew300t Firmware X30 Pro FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. |
1Ruijie 2Rg Ew1800gx Firmware Rg Ew300r FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_re...Show more |
1Ruijie 2Rg Ew1200g Pro Firmware Rg Ew1200r FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_...Show more |
1Ruijie 2M18 Ew Firmware Rg Ew300g Pro FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. |
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_service in file /usr/lib/lua/luci/controller/admin/service.lua. |
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_tcpdump in file /usr/lib/lua/luci/controller/admin/common_tcpdump.lua. |
1Ruijie 2Rg Ew1200 Firmware Rg X60 FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/...Show more |
1Ruijie 2Rg Ew1200 Firmware Rg Ew300 Pro FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/...Show more |
1Ruijie 4Reyee Os Rg Eap602 FirmwareRg Est310 V2 Firmware+1 moreJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_...Show more |
1Ruijie 4Reyee Os Rg Eap602 FirmwareRg Est310 V2 Firmware+1 moreJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_networkId_merge.lu...Show more |
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the check_changes in file /usr/lib/lua/luci/controller/admin/common.lua. |
1Ruijie 2Be50 Firmware Rg Ew1300g FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1.00/V2.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnec...Show more |
2Ruijie Ruijienetworks2Reyee Os Rg Rap2200(e) FirmwareJun 17, 2026 Dec 11, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. |
squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin...Show more |
A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the '...Show more |
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control...Show more |