← Back
CWE-78

6,747 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,747)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nintendo
1Wi Fi Network Adaptor Wap 001 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.
1Airspan
1Airvelocity 1500 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This i...Show more
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.Show less
1Vr Calendar Project
1Vr Calendar
Jun 17, 2026
Aug 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
1Tenda
1W6 Firmware
Jun 17, 2026
Aug 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.
1Cisco
9Rv160 Firmware
Rv160w FirmwareRv260 Firmware+6 more
Jun 17, 2026
Aug 10, 2022
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an...Show more
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Tcl
1Linkhub Mesh Wifi Ac1200
Jun 17, 2026
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacke...Show more
An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.Show less
1Tcl
1Linkhub Mesh Wifi Ac1200
Jun 17, 2026
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An atta...Show more
An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.Show less
1Rashim
1Michlol
Jun 17, 2026
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allow...Show more
Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in order to achieve his goals is to change the value of the ptMsl parameter and then the attacker can access sensitive data that he not supposed to access because its belong to another user.Show less
1Apache
1Hadoop
Jun 17, 2026
Aug 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBoo...Show more
Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It has been used in Hadoop 2.x for yarn localization, which does enable remote code execution. It is used in Apache Spark, from the SQL command ADD ARCHIVE. As the ADD ARCHIVE command adds new binaries to the classpath, being able to execute shell scripts does not confer new permissions to the caller. SPARK-38305. "Check existence of file before untarring/zipping", which is included in 3.3.0, 3.1.4, 3.2.2, prevents shell commands being executed, regardless of which version of the hadoop libraries are in use. Users should upgrade to Apache Hadoop 2.10.2, 3.2.4, 3.3.3 or upper (including HADOOP-18136).Show less
1Synology
1Diskstation Manager
Jun 17, 2026
Aug 3, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to...Show more
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.Show less
1S3 Kilatstorage Project
1S3 Kilatstorage
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package s3-kilatstorage.
1Ibm
1Cics Tx
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
IBM CICS TX 11.1 could allow allow an attacker with physical access to the system to execute code due using a back and refresh attack. IBM X-Force ID: 229312.
1Dlink
1Dsl 3782 Firmware
Jun 17, 2026
Jul 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160.
1Synology
1Diskstation Manager
Jun 17, 2026
Jul 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated u...Show more
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors.Show less
1Hestiacp
1Control Panel
Jun 17, 2026
Jul 27, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Jul 27, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Jul 27, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
1Cisco
5Application Extension Platform
Rv110w FirmwareRv130 Firmware+2 more
Jun 17, 2026
Jul 22, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected devi...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.Show less
1Cisco
5Application Extension Platform
Rv110w FirmwareRv130 Firmware+2 more
Jun 17, 2026
Jul 21, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected devi...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.Show less
1Cisco
5Application Extension Platform
Rv110w FirmwareRv130 Firmware+2 more
Jun 17, 2026
Jul 21, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected devi...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient validation of user fields within incoming HTTP packets. An attacker could exploit these vulnerabilities by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device with root-level privileges or to cause the device to restart unexpectedly, resulting in a DoS condition. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.Show less