← Back
CWE-78

6,728 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,728)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Hg8045q Firmware
Jun 17, 2026
Aug 13, 2021
N/A· v4
6.7 MEDIUM· v3
6.9 MEDIUM· v2
There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is disabled by default, attackers with administrator privilege could execute part of commands.
1Sunhillo
1Sureline
Jun 17, 2026
Aug 13, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
1Nagios
1Nagios Xi Watchguard Wizard
Jun 17, 2026
Aug 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).
1Nagios
1Nagios Xi Switch Wizard
Jun 17, 2026
Aug 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).
1Quectel
1Eg25 G Firmware
Jun 17, 2026
Aug 12, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Aug 11, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version...Show more
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 9.0 version 9.0.10 through PAN-OS 9.0.14; PAN-OS 9.1 version 9.1.4 through PAN-OS 9.1.10; PAN-OS 10.0 version 10.0.7 and earlier PAN-OS 10.0 versions; PAN-OS 10.1 version 10.1.0 through PAN-OS 10.1.1. Prisma Access firewalls and firewalls running PAN-OS 8.1 versions are not impacted by this issue.Show less
1Siemens
1Sinec Network Management System
Jun 17, 2026
Aug 10, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authe...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges could exploit this vulnerability to execute arbitrary code on the system with system privileges.Show less
1Rconfig
1Rconfig
Jun 17, 2026
Aug 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
1Dell
1Openmanage Enterprise
Jun 17, 2026
Aug 9, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated malicious user with high privileges may potentially exploit this vulnerabi...Show more
Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tools. A remote authenticated malicious user with high privileges may potentially exploit this vulnerability to execute arbitrary OS commands.Show less
1Prolink
1Prc2402m Firmware
Jun 17, 2026
Aug 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is pas...Show more
In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.Show less
1Prolink
1Prc2402m Firmware
Jun 17, 2026
Aug 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivial command injection where the value of the TR069_local_port parameter...Show more
In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivial command injection where the value of the TR069_local_port parameter is passed directly to system.Show less
1Advantech
1R Seenet
Jun 17, 2026
Aug 5, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can...Show more
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trigger this vulnerability.Show less
1Cisco
1Small Business Rv Series Router Firmware
Jun 17, 2026
Aug 4, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the unde...Show more
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device using root-level privileges. Due to the nature of the vulnerability, only commands without parameters can be executed.Show less
1Fortinet
1Fortisandbox
Jun 17, 2026
Aug 4, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the...Show more
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized code or commands via specifically crafted HTTP requests.Show less
1Electronjs
1Poddycast
Jun 17, 2026
Aug 3, 2021
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the...Show more
Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the HTML characters of the podcast information obtained from the Feed, which allows the injection of HTML and JS code (cross-site scripting). Being an application made in electron, cross-site scripting can be scaled to remote code execution, making it possible to execute commands on the machine where the application is running. The vulnerability is patched in Poddycast version 0.8.1.Show less
3Debian
OracleRuby Lang
3Debian Linux
Jd Edwards Enterpriseone ToolsRdoc
Jun 17, 2026
Jul 30, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
1Gitlogplus Project
1Gitlogplus
Jun 17, 2026
Jul 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
1Ivanti
1Mobileiron
Jun 17, 2026
Jul 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
1Akkadianlabs
2Ova Appliance
Provisioning Manager
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue wa...Show more
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).Show less
1Sage
1Syracuse
Jun 17, 2026
Jul 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be de...Show more
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.Show less