← Back
CWE-78

6,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asciidoctor Include Ext Project
1Asciidoctor Include Ext
Jun 17, 2026
Apr 1, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arb...Show more
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. This attack is possible even when `allow-uri-read` is disabled! The problem has been patched in the referenced commits.Show less
1Raspberrymatic
1Raspberrymatic
Jun 17, 2026
Mar 31, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware line of IoT devices. A Remote Code Execution (RCE) vulnerability in the file upload...Show more
RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware line of IoT devices. A Remote Code Execution (RCE) vulnerability in the file upload facility of the WebUI interface of RaspberryMatic exists. Missing input validation/sanitization in the file upload mechanism allows remote, unauthenticated attackers with network access to the WebUI interface to achieve arbitrary operating system command execution via shell metacharacters in the HTTP query string. Injected commands are executed as root, thus leading to a full compromise of the underlying system and all its components. Versions after `2.31.25.20180428` and prior to `3.63.8.20220330` are affected. Users are advised to update to version `3.63.8.20220330` or newer. There are currently no known workarounds to mitigate the security impact and users are advised to update to the latest version available.Show less
1Ntt East
4Og410xa Firmware
Og410xi FirmwareOg810xa Firmware+1 more
Jun 17, 2026
Mar 31, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially craft...Show more
Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.Show less
1Totolink
1Ar3100r Firmware
Jul 9, 2026
Mar 30, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection...Show more
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.Show less
1Dlink
1Dir 820l Firmware
Jul 9, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
1Netgear
1R8500 Firmware
Jun 17, 2026
Mar 26, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan...Show more
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameter.Show less
1Netgear
1R8500 Firmware
Jun 17, 2026
Mar 26, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to admin_account.cgi.
1Netgear
1R8500 Firmware
Jun 17, 2026
Mar 26, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi.
1Gnome
1Ocrfeeder
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.
1Vmware
1Carbon Black App Control
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious act...Show more
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.Show less
1Okta
1Advanced Server Access
Jun 17, 2026
Mar 23, 2022
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the vict...Show more
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system.Show less
1Rockwellautomation
1Factorytalk Assetcentre
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in R...Show more
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.Show less
1Snapt
1Aria
Jun 17, 2026
Mar 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands.
1Otrs
3Otrs
Otrs ItsmOtrs Storm
Jun 17, 2026
Mar 21, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Specially crafted string in OTRS system configuration can allow the execution of any system command.
1Contao
1Contao
Jun 17, 2026
Mar 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
1Tenda
1Ac9 Firmware
Jun 17, 2026
Mar 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function.
1Tenda
1Ac9 Firmware
Jun 17, 2026
Mar 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.
1Pascom
1Cloud Phone System
Jun 17, 2026
Mar 18, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote attackers to execute arbitrary code via shell metacharacters.