← Back
CWE-78

6,732 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,732)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Controlup
1Real Time Agent
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the ProcessActionRequest WCF method.
1Foxit
2Pdf Editor
Pdf Reader
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.
1Foxit
2Pdf Editor
Pdf Reader
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.
1Netgear
1R6700 Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command...Show more
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via preconfigured values.Show less
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the device is vulnerable to...Show more
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the device is vulnerable to command injection as root.Show less
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command injection as root by supplying a malformed parameter.
1Zyxel
12Gs1900 10hp Firmware
Gs1900 16 FirmwareGs1900 24 Firmware+9 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.
1Zyxel
14Gs1900 10hp Firmware
Gs1900 16 FirmwareGs1900 24 Firmware+11 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vu...Show more
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.Show less
1Gerapy
1Gerapy
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.
1Netgear
18D7800 Firmware
Ex2700 FirmwareLbr1020 Firmware+15 more
Jun 17, 2026
Dec 26, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6....Show more
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6.5.20, LBR20 before 2.6.5.32, R6700AX before 1.0.10.110, R7800 before 1.0.2.86, R8900 before 1.0.5.38, R9000 before 1.0.5.38, RAX10 before 1.0.10.110, RAX120v1 before 1.2.3.28, RAX120v2 before 1.2.3.28, RAX70 before 1.0.10.110, RAX78 before 1.0.10.110, XR450 before 2.3.2.130, XR500 before 2.3.2.130, and XR700 before 1.0.1.46.Show less
2Fedoraproject
Redhat
8Enterprise Linux
Enterprise Linux EusEnterprise Linux Server Aus+5 more
Jun 17, 2026
Dec 23, 2021
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially c...Show more
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.Show less
1Myscada
1Mypro
Jun 17, 2026
Dec 23, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
1Myscada
1Mypro
Jun 17, 2026
Dec 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
1Myscada
1Mypro
Jun 17, 2026
Dec 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
2Redhat
Theforeman
2Foreman
Satellite
Jun 17, 2026
Dec 23, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threa...Show more
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.Show less
1Myscada
1Mypro
Jun 17, 2026
Dec 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
1Myscada
1Mypro
Jun 17, 2026
Dec 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
1Tp Link
1Tl Wr802n Firmware
Jun 17, 2026
Dec 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.
1Lantronix
1Premierwave 2050 Firmware
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execu...Show more
An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Lantronix
1Premierwave 2050 Firmware
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker...Show more
An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less