← Back
CWE-78

6,722 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,722)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linksys
1E8450 Firmware
Jun 17, 2026
Jan 21, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.
1Tenda
3Ac10 Firmware
Ac18 FirmwareAc8 Firmware
Jun 17, 2026
Jan 17, 2025
8.6 HIGH· v4
7.2 HIGH· v3
8.3 HIGH· v2
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Han...Show more
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
-
-
Jun 17, 2026
Jan 17, 2025
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM allows Local Code Inclusion.This issue affects N...Show more
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM allows Local Code Inclusion.This issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1 through 2.2.6.19. The `commit_multicast` page used to configure multicasts in the modem's web administration interface uses improperly parses incoming data from the request before passing it to an `eval` statement in a bash script. This allows attackers to inject arbitrary shell commands.Show less
-
-
Jun 17, 2026
Jan 16, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.
1Totolink
1X5000r Firmware
Jun 17, 2026
Jan 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.
-
-
Jun 17, 2026
Jan 15, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network.