CWE-78
5,964 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability can allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOG...Show more |
Dell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerability may allow an authenticated user with ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_C...Show more |
1Cisco 12Catalyst Sd Wan Manager Sd Wan Vbond OrchestratorSd Wan Vmanage+9 moreNov 21, 2024 May 6, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Administrator privileges on the underlying operating system. This vulnerab...Show more |
1Cisco 1Hyperflex Hx Data Platform Oct 28, 2025 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information a...Show more |
1Cisco 1Hyperflex Hx Data Platform Oct 28, 2025 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information a...Show more |
1Cisco 1Enterprise Nfv Infrastructure Software Nov 21, 2024 May 6, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to perform a command injection attack on an affected device. The vulnerability is due to insufficient v...Show more |
1Cisco 6Wap125 Firmware Wap131 FirmwareWap150 Firmware+3 moreNov 21, 2024 May 6, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information...Show more |
1Iwt 1Facesentry Access Control System Firmware Nov 21, 2024 May 4, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root...Show more |
The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. |
1Dell 1Openmanage Enterprise Modular Nov 21, 2024 Apr 30, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with low privileges may potentially exploit the vulnerability to escape from t...Show more |
1Systeminformation 1Systeminformation Nov 21, 2024 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has been fixed with a pa...Show more |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseNov 21, 2024 Apr 29, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be e...Show more |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseNov 21, 2024 Apr 29, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlyin...Show more |
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affecte...Show more |
1Chinamobile 1An Lianbao Wf 1 Firmware Nov 21, 2024 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_WAN_CONNECT parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Nov 21, 2024 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Nov 21, 2024 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Nov 21, 2024 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink...Show more |
1Chinamobile 1An Lianbao Wf 1 Firmware Nov 21, 2024 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Nov 21, 2024 Apr 29, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter. |