CWE-78
6,732 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attack...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can m...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenticated HTTP requests to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An...Show more |
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17. |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Dec 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit v...Show more |
1Fiberhome 6Aan5506 04 G2g Firmware An5506 01 A FirmwareAn5506 01 B Firmware+3 moreJul 9, 2026 Dec 16, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping d...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Dec 14, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to...Show more |
1Ibm 1Spectrum Copy Data Management Jun 17, 2026 Dec 13, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Ad...Show more |
1Anker 1Eufy Homebase 2 Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary comma...Show more |
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more |
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more |
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more |
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more |
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute co...Show more |