← Back
CWE-78

5,964 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (5,964)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qsan
1Xevo
Nov 21, 2024
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO...Show more
OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.Show less
1Qsan
1Xevo
Nov 21, 2024
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerability has been solved with the updated ve...Show more
OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.Show less
1Qsan
1Storage Manager
Nov 21, 2024
Jul 7, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
1Qsan
1Storage Manager
Nov 21, 2024
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the u...Show more
QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.Show less
1Qsan
1Storage Manager
Nov 21, 2024
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the...Show more
QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.Show less
1Elecom
11Wrc 300febk Firmware
Wrc 733febk FirmwareWrc F300nf Firmware+8 more
Nov 21, 2024
Jul 7, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated network-adjacent attacker to execute an arbitr...Show more
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated network-adjacent attacker to execute an arbitrary OS command via unspecified vectors.Show less
1Qnap
2Qts
Quts Hero
Nov 21, 2024
Jul 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP S...Show more
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217.Show less
1Qnap
2Qts
Quts Hero
Nov 21, 2024
Jul 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP S...Show more
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build 20210107. QNAP Systems Inc. QuTS hero versions prior to h4.5.1.1582 build 20210217.Show less
1Mcafee
1Mvision Edr
Feb 24, 2026
Jun 29, 2021
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality '...Show more
A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.Show less
1Wincred Project
1Wincred
Nov 21, 2024
Jun 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_proces...Show more
This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.Show less
1Inkdrop
1Inkdrop
Nov 21, 2024
Jun 28, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop.
2Hitachi
Nec
7Nas Gateway Nh4a Firmware
Nas Gateway Nh4b FirmwareNas Gateway Nh4c Firmware+4 more
Nov 21, 2024
Jun 28, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/Nh8c versions prior to...Show more
Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/Nh8c versions prior to FOS 6.4.3-08(NEC3.4.2) allow remote authenticated attackers to execute arbitrary OS commands with root privileges via unspecified vectors.Show less
1Weidmueller
8Ie Wl Bl Ap Cl Eu Firmware
Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 more
Nov 21, 2024
Jun 25, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause ex...Show more
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various requests while authenticated as a high privilege user to trigger this vulnerability.Show less
1Weidmueller
8Ie Wl Bl Ap Cl Eu Firmware
Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 more
Nov 21, 2024
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflect...Show more
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.Show less
1Weidmueller
8Ie Wl Bl Ap Cl Eu Firmware
Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 more
Nov 21, 2024
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be r...Show more
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.Show less
1Weidmueller
8Ie Wl Bl Ap Cl Eu Firmware
Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 more
Nov 21, 2024
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file ca...Show more
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.Show less
1Fidelissecurity
2Deception
Network
Nov 21, 2024
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on t...Show more
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.Show less
1Fidelissecurity
2Deception
Network
Nov 21, 2024
Jun 25, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring F...Show more
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Nov 21, 2024
Jun 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
1Qnap
1Qts
Nov 21, 2024
Jun 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This is...Show more
A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.3.6.1663 Build 20210504; versions prior to 4.3.3.1624 Build 20210416. This issue does not affect: QNAP Systems Inc. QTS 4.5.3. QNAP Systems Inc. QuTS hero h4.5.3. QNAP Systems Inc. QuTScloud c4.5.5.Show less