CWE-78
6,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packe...Show more |
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packe...Show more |
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted pac...Show more |
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted...Show more |
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted pa...Show more |
1Inhandnetworks 1Inrouter 900 Firmware Jun 17, 2026 Apr 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a cr...Show more |
1Dell 1Emc Unity Operating Environment Jun 17, 2026 Apr 8, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges. |
1Dell 1Emc Unity Operating Environment Jun 17, 2026 Apr 8, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system. |
D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system o...Show more |
ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt...Show more |
1Wavlink 1Wl Wn531p3 Firmware Jun 17, 2026 Apr 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/ad...Show more |
1Drtrustusa 1Icheck Connect Bp Monitor Bp Testing 118 Firmware Jul 9, 2026 Apr 7, 2022 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE. |
An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands v...Show more |
1Fortinet 3Fortianalyzer FortimanagerFortiportalJun 17, 2026 Apr 6, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and b...Show more |
An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating syste...Show more |
Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underly...Show more |
1Dcnglobal 1S4600 10p Si Firmware Jun 17, 2026 Apr 5, 2022 N/A· v4 7.4 HIGH· v3 7.2 HIGH· v2 An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to...Show more |
1Moxa 4Nport Iaw5150a 12i/o Firmware Nport Iaw5150a 6i/o FirmwareNport Iaw5250a 12i/o Firmware+1 moreJun 17, 2026 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands. |
1Auvesy Mdt 2Autosave Autosave For System PlatformJun 17, 2026 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be...Show more |
Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field. |