← Back
CWE-78

5,947 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (5,947)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nec
1Aterm Wg1200hp Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.
1Nec
1Aterm Wg1200hp Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.
1Nec
1Aterm Wg1200hp Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.
1Dlink
2Dir 818l(w) Firmware
Dir 860l Firmware
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service of the cgibin binary via an "&&" substring in the service parameter....Show more
On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service of the cgibin binary via an "&&" substring in the service parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-6530.Show less
1Facebook
1React Dev Utils
May 6, 2025
Dec 31, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker wh...Show more
react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the server (either via CSRF or by direct request) to execute arbitrary commands on the targeted system. This issue affects multiple branches: 1.x.x prior to 1.0.4, 2.x.x prior to 2.0.2, 3.x.x prior to 3.1.2, 4.x.x prior to 4.2.2, and 5.x.x prior to 5.0.2.Show less
1Guardzilla
2180 Indoor Firmware
180 Outdoor Firmware
May 6, 2025
Dec 31, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.
1Skydevices
1Sky Elite 6.0l+ Firmware
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys contains a pre-installed platform app with a package name of com.fw.upgrade...Show more
The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys contains a pre-installed platform app with a package name of com.fw.upgrade.sysoper (versionCode=238, versionName=2.3.8) that contains an exported broadcast receiver app component named com.adups.fota.sysoper.WriteCommandReceiver that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. The com.fw.upgrade.sysoper app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, obtain the user's text messages, and more.Show less
1Leagoo
1P1 Firmware
Nov 21, 2024
Dec 28, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidden root privilege escalation capability to achieve command execution as...Show more
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidden root privilege escalation capability to achieve command execution as the root user. They have made modifications that allow a user with physical access to the device to obtain a root shell via ADB by modifying read-only system properties at runtime. Specifically, modifying the ro.debuggable and the ro.secure system properties to a certain value and then restarting the ADB daemon allows for a root shell to be obtained via ADB.Show less
1Trendnet
1Tew 673gru Firmware
Nov 21, 2024
Dec 20, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_s...Show more
TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.Show less
1Logitech
1Harmony Hub Firmware
Nov 21, 2024
Dec 20, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.
1Phkp Project
1Phkp
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in function pgp_exec() phkp.php:98 that...Show more
PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in function pgp_exec() phkp.php:98 that can result in It is possible to manipulate gpg-keys or execute commands remotely. This attack appear to be exploitable via HKP-Api: /pks/lookup?search.Show less
1Vyos
1Vyos
Nov 21, 2024
Dec 17, 2018
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuing various shell special characters with certain commands, an authentica...Show more
A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuing various shell special characters with certain commands, an authenticated operator user can break out of the management shell and gain access to the underlying Linux shell. The user can then run arbitrary operating system commands with the privileges afforded by their account.Show less
1Geutebrueck
2G Cam/efd 2251 Firmware
G Cam/ewpc 2275 Firmware
Nov 21, 2024
Dec 14, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS system command injection as root.
1D Link
2Dir 605l Firmware
Dir 619l Firmware
Nov 21, 2024
Dec 11, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd allows remote authenticated users to execute arbitrary OS commands via the sysCmd POST parameter.
1Moxa
1Nport W2x50a Firmware
Nov 21, 2024
Dec 6, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/...Show more
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/webSettingProfileSecurity can result in running OS commands as the root user.Show less
1Moxa
1Nport W2x50a Firmware
Nov 21, 2024
Dec 6, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/...Show more
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/net_WebPingGetValue can result in running OS commands as the root user. This is similar to CVE-2017-12120.Show less
1Misp
1Misp
Nov 21, 2024
Dec 6, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious au...Show more
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.Show less
1Craftercms
1Crafter Cms
Nov 21, 2024
Dec 6, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemar...Show more
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.Show less
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.