CWE-78
6,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dlink 1Dir 823 Pro Firmware Jun 17, 2026 May 2, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows attackers to execute arbitrary commands via the system_time_timezone par...Show more |
1Tenda 2Ax1803 Firmware Ax1806 FirmwareJun 17, 2026 May 2, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function |
D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. |
USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are blocked but (for example) an OS command for base64 decoding is not blocked....Show more |
1Bender 2Cc612 Firmware Icc15xx FirmwareJun 17, 2026 Apr 27, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges. |
1Telesquare 1Sdt Cs3b1 Firmware Jun 17, 2026 Apr 27, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication. |
In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization. |
1Git Interface Project 1Git Interface Jun 17, 2026 Apr 22, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Apr 18, 2022 N/A· v4 6.8 MEDIUM· v3 7.1 HIGH· v2 Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default ad...Show more |
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code...Show more |
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input vali...Show more |
1Yokogawa 2B/m9000 Vp Centum VpJun 17, 2026 Apr 15, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02, which may allow an attacker wh...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureW...Show more |
1Npm Dependency Versions Project 1Npm Dependency Versions Jun 17, 2026 Apr 12, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a...Show more |
1Dlink 10Dir 1360 Firmware Dir 1760 FirmwareDir 1960 Firmware+7 moreJun 17, 2026 Apr 11, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root. |
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior. |
1Zyxel 32Ax7501 B0 Firmware Dx5401 B0 FirmwareEmg3525 T50b Firmware+29 moreJun 17, 2026 Apr 11, 2022 N/A· v4 8.0 HIGH· v3 7.7 HIGH· v2 A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN inte...Show more |
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packe...Show more |
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packe...Show more |
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packe...Show more |