← Back
CWE-78

6,657 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Api Connect
Jun 17, 2026
Apr 15, 2019
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-For...Show more
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-Force ID: 159123.Show less
1Apache
1Tomcat
Jun 17, 2026
Apr 15, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE...Show more
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange's blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).Show less
1Xerox
5Colorqube 8700 Firmware
Colorqube 8900 FirmwareColorqube 9301 Firmware+2 more
Jun 17, 2026
Apr 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depend...Show more
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.Show less
1Verizon
1Fios Quantum Gateway G1100 Firmware
Jun 17, 2026
Apr 11, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access c...Show more
Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname.Show less
1Ui
1Edgeswitch X
Jun 17, 2026
Apr 10, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root.
1Ui
1Edgeswitch X
Jun 17, 2026
Apr 10, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user.
1Zyxel
1Nas326 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.
1Reolink
5C1 Pro Firmware
C2 Pro FirmwareRlc 410w Firmware+2 more
Jun 17, 2026
Apr 8, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharac...Show more
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.Show less
1Advantech
1Webaccess
Jun 17, 2026
Apr 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of proper validation of user-supplied data, may allow remote code execution.
1Postgresql
1Postgresql
Jun 17, 2026
Apr 1, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. T...Show more
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.Show less
1Dlink
1Dsl 3782 Firmware
Nov 21, 2024
Apr 1, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT para...Show more
An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT parameter.Show less
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Nov 21, 2024
Apr 1, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
1Audiocodes
1420hd Ip Phone Firmware
Jun 17, 2026
Apr 1, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI,...Show more
An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via shell metacharacters in the query string.Show less
1Synology
1Router Manager
Nov 21, 2024
Apr 1, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
1Synology
1Diskstation Manager
Jan 14, 2025
Apr 1, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
1Grandstream
1Ucm6204 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
1Grandstream
1Gxv3611ir Hd Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.
1Grandstream
2Gxv3370 Firmware
Wp820 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field.
1Grandstream
1Gwn7610 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_fro...Show more
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.Show less
1Grandstream
2Gwn7000 Firmware
Gwn7610 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.