← Back
CWE-78

6,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Galsys
1Nts 6002 Gps Firmware
Jun 17, 2026
May 9, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-manage...Show more
An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected (Ping, Traceroute, and DNS Lookup) and their respective input fields (ping_address, trace_address, nslookup_address). NOTE: this is disputed by the Supplier because the affected components were never shipped in a production release (they were only present in development releases), and because no privilege boundary is crossed (an applicable "authenticated attacker" always also has the supported ability to make an SSH connection as root).Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully co...Show more
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a careful...Show more
It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully co...Show more
It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully...Show more
It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefull...Show more
It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payloadShow less
1Tenda
1Tx9 Pro Firmware
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).
1Articatech
1Artica Proxy
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
1Cisco
4Rv340 Firmware
Rv340w FirmwareRv345 Firmware+1 more
Jun 17, 2026
May 4, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying oper...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by sending malicious input to an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system of the affected device. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device.Show less
1Cisco
4Rv340 Firmware
Rv340w FirmwareRv345 Firmware+1 more
Jun 17, 2026
May 4, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying oper...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by sending malicious input to an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system of the affected device. To exploit these vulnerabilities, an attacker would need to have valid Administrator credentials on the affected device.Show less
1Tenda
1Ac15 Firmware
Jun 17, 2026
May 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arb...Show more
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command executionShow less
1Eve Ng
1Eve Ng
Jun 17, 2026
May 4, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editi...Show more
An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.Show less
1Fusionpbx
1Fusionpbx
Jun 17, 2026
May 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
1Ruijienetworks
1Reyeeos
Jul 9, 2026
May 4, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.
6Debian
FedoraprojectNetapp+3 more
35A250 Firmware
A700s FirmwareActive Iq Unified Manager+32 more
Jun 17, 2026
May 3, 2022
N/A· v4
7.3 HIGH· v3
10.0 HIGH· v2
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating sys...Show more
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).Show less
1Mitrastar
1Gpt 2541gnac N1 Firmware
Jun 17, 2026
May 3, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".