← Back
CWE-78

6,658 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Meeting Server
Jun 17, 2026
Jun 20, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation...Show more
A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials could exploit this vulnerability by injecting crafted arguments during command execution. A successful exploit could allow the attacker to perform arbitrary code execution as root on an affected product.Show less
1Sony
8R5c Firmware
Wd65 FirmwareWd75 Firmware+5 more
Nov 21, 2024
Jun 19, 2019
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.
1Vtech
1Storio Max Firmware
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Reque...Show more
VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Requests submitted to this service are checked for a string of random characters followed by the name of an Android activity to start. Activities are started by inserting their name into a string that is executed in a shell command. By inserting metacharacters this can be exploited to run arbitrary commands as root. The requests also match those of the HTTP protocol and can be triggered on any web page rendered on the device by requesting resources stored at an http://127.0.0.1:1668/ URI, as demonstrated by the http://127.0.0.1:1668/dacdb70556479813fab2d92896596eef?';{ping,example.org}' URL.Show less
1Westerndigital
1My Book Live Firmware
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered...Show more
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,Show less
1Cerio
1Dt 300n Firmware
Nov 21, 2024
Jun 18, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in Octobe...Show more
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.Show less
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Jun 17, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on th...Show more
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.Show less
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Jun 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execu...Show more
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host. This can further lead to remote code execution when combined with an XSS vulnerability also present in the FusionPBX Operator Panel module.Show less
1Solarwinds
2Serv U Ftp Server
Serv U Mft Server
Jun 17, 2026
Jun 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
1Webmin
1Webmin
Jun 17, 2026
Jun 15, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
1Orangehrm
1Orangehrm
Jun 17, 2026
Jun 15, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbitrary command execution.
1Hootoo
1Tripmate Titan Ht Tm05 Firmware
Nov 21, 2024
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_tab...Show more
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request.Show less
1Zte
1Mf920 Firmware
Jun 17, 2026
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific...Show more
All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfaces do not adequately verify parameters, an attacker can execute arbitrary commands through specific interfaces.Show less
1Zte
1Wf820+ Lte Outdoor Cpe Firmware
Jun 17, 2026
Jun 11, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take advantage of this vulne...Show more
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take advantage of this vulnerability to control the user terminal system.Show less
1Dlink
1Dir 818l(w) Firmware
Jun 17, 2026
Jun 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.
1Belkin
1Crock Pot Smart Slow Cooker With Wemo Firmware
Jun 17, 2026
Jun 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to exec...Show more
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.Show less
1Moxa
1Awk 3121 Firmware
Nov 21, 2024
Jun 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to ex...Show more
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to command injection via shell metacharacters.Show less
1Moxa
1Awk 3121 Firmware
Nov 21, 2024
Jun 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However,...Show more
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_privatePass" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.Show less
1Moxa
1Awk 3121 Firmware
Nov 21, 2024
Jun 7, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functio...Show more
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.Show less
1Ui
1Edgeos
Nov 21, 2024
Jun 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/vyatta-cfg/templates/system/static-host-mapping/host-name/node.def does...Show more
Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/vyatta-cfg/templates/system/static-host-mapping/host-name/node.def does not sanitize the 'alias' or 'ips' parameter for shell metacharacters.Show less
1Thinstation Project
1Thinstation
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Command injection is possible in ThinStation through 6.1.1 via shell metacharacters after the cgi-bin/CdControl.cgi action= substring, or after the cgi-bin/VolControl.cgi OK= substring.