← Back
CWE-78

6,747 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,747)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoom
1Rooms
Jun 17, 2026
Jan 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.
1Wifey Project
1Wifey
Jun 17, 2026
Jan 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.
1Nexxtsolutions
1Amp300 Firmware
Jun 17, 2026
Jan 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authe...Show more
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is requiredShow less
1Exec Local Bin Project
1Exec Local Bin
Jun 17, 2026
Jan 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.
1Control Webpanel
1Webpanel
Jun 17, 2026
Jan 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Jan 5, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arb...Show more
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Jan 5, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arb...Show more
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Jan 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arb...Show more
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Show less
1Window Control Project
1Window Control
Jun 17, 2026
Jan 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.
1Fortinet
1Fortiadc
Jun 17, 2026
Jan 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through...Show more
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6.0.4, FortiADC version 5.4.0 through 5.4.5 may allow an attacker to execute unauthorized code or commands via specifically crafted HTTP requests.Show less
1Fortinet
1Fortitester
Jun 17, 2026
Jan 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an a...Show more
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitrary commands in the underlying shell.Show less
1Changingtec
1Servisign
Jun 17, 2026
Jan 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, wh...Show more
ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers command injection and allows the attacker to execute arbitrary system command to perform arbitrary system operation or disrupt service.Show less
1Realtek
2Usdk
Xpon Software Development Kit
Jun 17, 2026
Jan 3, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerability to perform command injection attacks, to execute arbitrary system...Show more
Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.Show less
1Trendnet
1Tew 755ap Firmware
Jun 17, 2026
Dec 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.
1Trendnet
1Tew 755ap Firmware
Jun 17, 2026
Dec 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
1Forthebadge
1For The Badge
Jun 17, 2026
Dec 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .github/workflows/combine-prs.yml. The manipulation leads to os command inj...Show more
A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .github/workflows/combine-prs.yml. The manipulation leads to os command injection. The name of the patch is 55b5a234c0fab935df5fb08365bc8fe9c37cf46b. It is recommended to apply a patch to fix this issue. VDB-216842 is the identifier assigned to this vulnerability.Show less
1Intelbras
1Wifiber 120ac Inmesh Firmware
Jun 17, 2026
Dec 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.
1Ip Com
1M50 Firmware
Jun 17, 2026
Dec 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET re...Show more
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.Show less
1Ip Com
1M50 Firmware
Jun 17, 2026
Dec 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.
1Ip Com
1M50 Firmware
Jun 17, 2026
Dec 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.