← Back
CWE-78

6,732 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,732)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Nov 4, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Nov 4, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Nov 4, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.
1Bg Tek
1Coslat
Jun 17, 2026
Nov 4, 2024
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Comma...Show more
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection, Privilege Escalation. This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that the product is not supported.Show less
1Davidlingren
1Media Library Assistant
Jun 17, 2026
Nov 4, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media...Show more
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.19.Show less
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Nov 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Nov 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Nov 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Nov 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
1Draytek
1Vigor3900 Firmware
Jun 17, 2026
Nov 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
-
-
Jun 17, 2026
Nov 1, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on...Show more
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server.Show less
-
-
Jun 17, 2026
Oct 31, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.
-
-
Jun 17, 2026
Oct 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.
1Cyberpanel
1Cyberpanel
Jun 17, 2026
Oct 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code exe...Show more
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.Show less
1Cyberpanel
1Cyberpanel
Aug 5, 2026
Oct 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatu...Show more
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.Show less
1Hitachienergy
3Tro610 Firmware
Tro620 FirmwareTro670 Firmware
Jun 17, 2026
Oct 29, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute comm...Show more
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive than what the write privilege intends.Show less
1Zte
1Mf258k Pro Firmware
Jun 17, 2026
Oct 29, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary comman...Show more
There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.Show less
1Tenda
1Ac7 Firmware
Jun 17, 2026
Oct 28, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
1Tenda
1Ac7 Firmware
Jun 17, 2026
Oct 28, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
1Draytek
1Vigor2960 Firmware
Jun 17, 2026
Oct 28, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route...Show more
An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.Show less