CWE-78
6,666 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,666)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trendnet 3Tew 651br Firmware Tew 652brp FirmwareTew 652bru FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get_set.ccp lanHostCfg_HostName_1.1.1.0.0 parameter. |
1Barco 3Clickshare Cs 100 Firmware Clickshare Cse 200 FirmwareClickshare Cse 800 FirmwareJun 17, 2026 Dec 16, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS com...Show more |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. |
2Petwant Skymee2Petalk Ai Firmware Pf 103 FirmwareJun 17, 2026 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. |
2Apache Debian2Debian Linux SpamassassinNov 21, 2024 Dec 12, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid paramete...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption par...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter...Show more |
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. |
IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbi...Show more |
4Debian FedoraprojectGit Scm+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Dec 11, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found i...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on...Show more |
1Yachtcontrol 1Yachtcontrol Jun 17, 2026 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed...Show more |
1Supermicro 2X8sti F Bios X8sti F FirmwareJun 17, 2026 Dec 8, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires...Show more |
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject...Show more |
In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials. |