CWE-78
6,657 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,657)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-For...Show more |
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE...Show more |
1Xerox 5Colorqube 8700 Firmware Colorqube 8900 FirmwareColorqube 9301 Firmware+2 moreJun 17, 2026 Apr 12, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depend...Show more |
1Verizon 1Fios Quantum Gateway G1100 Firmware Jun 17, 2026 Apr 11, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access c...Show more |
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root. |
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user. |
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests. |
1Reolink 5C1 Pro Firmware C2 Pro FirmwareRlc 410w Firmware+2 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharac...Show more |
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution. |
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. T...Show more |
An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT para...Show more |
1Grandstream 6Gxp1610 Firmware Gxp1615 FirmwareGxp1620 Firmware+3 moreNov 21, 2024 Apr 1, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell. |
1Audiocodes 1420hd Ip Phone Firmware Jun 17, 2026 Apr 1, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI,...Show more |
Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command. |
Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command. |
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI. |
1Grandstream 1Gxv3611ir Hd Firmware Jun 17, 2026 Mar 30, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field. |
1Grandstream 2Gxv3370 Firmware Wp820 FirmwareJun 17, 2026 Mar 30, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field. |
1Grandstream 1Gwn7610 Firmware Jun 17, 2026 Mar 30, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_fro...Show more |
1Grandstream 2Gwn7000 Firmware Gwn7610 FirmwareJun 17, 2026 Mar 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request. |