← Back
CWE-78

5,964 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (5,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lantronix
1Premierwave 2050 Firmware
Nov 21, 2024
Dec 22, 2021
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An...Show more
An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Laravel
1Framework
Nov 21, 2024
Dec 20, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
1Goabode
1Iota All In One Security Kit Firmware
Nov 21, 2024
Dec 20, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit v...Show more
OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.0.2.23_6.9V_dev_t2_homekit_RF_2.0.19_s2_kvsABODE oz.Show less
1Fiberhome
6Aan5506 04 G2g Firmware
An5506 01 A FirmwareAn5506 01 B Firmware+3 more
Nov 21, 2024
Dec 16, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping d...Show more
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.Show less
1Sap
1Netweaver Application Server Abap
Nov 21, 2024
Dec 14, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to...Show more
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when executing with a certain transaction class builder. This could allow execution of arbitrary commands on the operating system, that could highly impact the Confidentiality, Integrity and Availability of the system.Show less
1Ibm
1Spectrum Copy Data Management
Nov 21, 2024
Dec 13, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Ad...Show more
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertificate function . A remote attacker could inject arbitrary shell commands which would be executed on the affected system. IBM X-Force ID: 214958.Show less
1Anker
1Eufy Homebase 2 Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary comma...Show more
A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution.Show less
1Gryphonconnect
1Gryphon Tower Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more
An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.Show less
1Gryphonconnect
1Gryphon Tower Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more
An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.Show less
1Gryphonconnect
1Gryphon Tower Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more
An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.Show less
1Gryphonconnect
1Gryphon Tower Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more
An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.Show less
1Gryphonconnect
1Gryphon Tower Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more
An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.Show less
1Gryphonconnect
1Gryphon Tower Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute com...Show more
An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.Show less
1Gryphonconnect
1Gryphon Tower Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same network can execute command...Show more
An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the web interface.Show less
1Fortinet
1Meru Firmware
Nov 21, 2024
Dec 9, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows attacker to execute unauthorized code or commands via crafted cli commands.
1Bosch
4Bosch Video Management System
Video Recording ManagerVideojet Decoder 7513 Firmware+1 more
Nov 21, 2024
Dec 8, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed...Show more
A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).Show less
1Fortinet
1Fortiweb
Nov 21, 2024
Dec 8, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to exec...Show more
Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.Show less
1Fortinet
1Fortiweb
Nov 21, 2024
Dec 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to e...Show more
Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to execute unauthorized code or commands via crafted parameters of HTTP requests.Show less
1Sonicwall
5Sma 200 Firmware
Sma 210 FirmwareSma 400 Firmware+2 more
Nov 21, 2024
Dec 8, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410 a...Show more
A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.Show less
1Sonicwall
5Sma 200 Firmware
Sma 210 FirmwareSma 400 Firmware+2 more
Sep 5, 2025
Dec 8, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerabili...Show more
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.Show less