CWE-78
6,666 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,666)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS comman...Show more |
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing...Show more |
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' via multiple parameters when creating a P...Show more |
The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticated user with high privileges to inject commands into the command shell of the T...Show more |
Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privileged network access for the configuration utility can execute arbitrary commands o...Show more |
1Dlink 1Dap 2695 Firmware Jun 17, 2026 Oct 27, 2025 2.0 LOW· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Update Handler. The manipulation leads to os command injection. The attack...Show more |
Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /api/aaa;/../register. |
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use |
Diagnostics command injection vulnerability |
Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode. This affects developm...Show more |
AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manager/radius/server_ping.php endpoint. The application constructs a shell command that includes the user...Show more |
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 an...Show more |
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions fr...Show more |
1Tp Link 13Er605 Firmware Er706w 4g FirmwareEr706w Firmware+10 moreJun 17, 2026 Oct 21, 2025 9.3 CRITICAL· v4 7.2 HIGH· v3 N/A· v2 A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. |
1Tp Link 13Er605 Firmware Er706w 4g FirmwareEr706w Firmware+10 moreJun 17, 2026 Oct 21, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. |
1Tp Link 13Er605 Firmware Er706w 4g FirmwareEr706w Firmware+10 moreJun 17, 2026 Oct 21, 2025 8.6 HIGH· v4 8.8 HIGH· v3 N/A· v2 An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |
GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulne...Show more |
1Microchip 1Timeprovider 4100 Firmware Jun 17, 2026 Oct 20, 2025 8.9 HIGH· v4 8.8 HIGH· v3 N/A· v2 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5. |
1Microchip 1Timeprovider 4100 Firmware Jun 17, 2026 Oct 20, 2025 8.9 HIGH· v4 8.8 HIGH· v3 N/A· v2 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5. |
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. |