CWE-78
5,947 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT para...Show more |
1Grandstream 6Gxp1610 Firmware Gxp1615 FirmwareGxp1620 Firmware+3 moreNov 21, 2024 Apr 1, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell. |
1Audiocodes 1420hd Ip Phone Firmware Nov 21, 2024 Apr 1, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI,...Show more |
Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command. |
Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command. |
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI. |
1Grandstream 1Gxv3611ir Hd Firmware Nov 21, 2024 Mar 30, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field. |
1Grandstream 2Gxv3370 Firmware Wp820 FirmwareNov 21, 2024 Mar 30, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field. |
1Grandstream 1Gwn7610 Firmware Nov 21, 2024 Mar 30, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_fro...Show more |
1Grandstream 2Gwn7000 Firmware Gwn7610 FirmwareNov 21, 2024 Mar 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request. |
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call. |
1Grandstream 5Gac2500 Firmware Gvc3202 FirmwareGxp2200 Firmware+2 moreNov 21, 2024 Mar 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manage...Show more |
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of...Show more |
1Node Opencv Project 1Node Opencv Nov 21, 2024 Mar 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands. |
An exploitable vulnerability exists in the verified boot protection of the CUJO Smart Firewall. It is possible to add arbitrary shell commands into the dhcpd.conf file, that persist across reboots and firmware updates, a...Show more |
1Raisecom 4Iscom Ht803g 1ge Firmware Iscom Ht803g U FirmwareIscom Ht803g W Firmware+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below, The...Show more |
1Raisecom 4Iscom Ht803g 1ge Firmware Iscom Ht803g U FirmwareIscom Ht803g W Firmware+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below. The...Show more |
1Systrome 3Cumilon Isg 600c Firmware Cumilon Isg 600h FirmwareCumilon Isg 800w FirmwareNov 21, 2024 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the description of an ISP file. The file networ...Show more |
If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2. |
www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands. |