CWE-78
5,947 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices. In the SetWiFiVerifyAlpha.php source code, the WPSPIN parameter is saved in...Show more |
2D Link Dlink2Dir 822 Firmware Dir 822 FirmwareNov 21, 2024 May 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink p...Show more |
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices. In the SetClientInfoDemo.php source code, the AudioM...Show more |
2D Link Dlink7Dir 818l(w) Firmware Dir 822 FirmwareDir 822 Firmware+4 moreNov 21, 2024 May 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAcc...Show more |
1D Link 2Dir 818l(w) Firmware Dir 822 FirmwareNov 21, 2024 May 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, th...Show more |
2Arubanetworks Siemens2Aruba Instant Scalance W1750d FirmwareNov 21, 2024 May 10, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker co...Show more |
2Arubanetworks Siemens2Aruba Instant Scalance W1750d FirmwareNov 21, 2024 May 10, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this a...Show more |
1Engeniustech 1Ews660ap Firmware Nov 21, 2024 May 9, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using different payloads and injecting multiple parameters. This vul...Show more |
1Sierrawireless 1Airlink Es450 Firmware Nov 21, 2024 May 6, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Management CenterNov 26, 2024 May 3, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. A...Show more |
1Cisco 1Secure Firewall Management Center Nov 26, 2024 May 3, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. A...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerabilit...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vul...Show more |
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 5, 2025 May 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenti...Show more |
3Debian OpensuseSigning Party Project3Debian Linux LeapSigning PartyNov 21, 2024 Apr 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID. |
8Barco BlackboxCrestron+5 more12Am 100 Firmware Am 101 FirmwareHd Wireless Presentation System Firmware+9 moreNov 3, 2025 Apr 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV...Show more |
1Crestron 2Am 100 Firmware Am 101 FirmwareNov 21, 2024 Apr 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to ex...Show more |
1Crestron 2Am 100 Firmware Am 101 FirmwareNov 21, 2024 Apr 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to exe...Show more |
In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciou...Show more |