← Back
CWE-78

6,175 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,175)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Igreks
3Milkystep Light
Milkystep ProfessionalMilkystep Professional Oem
May 6, 2026
Jun 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
1Buffalotech
7Bhr 4grv2 Firmware
Wex 300 FirmwareWhr 1166dhp Firmware+4 more
May 6, 2026
Jun 9, 2015
N/A· v4
N/A· v3
7.7 HIGH· v2
The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, and BHR-4GRV2 1.04 and earlier routers al...Show more
The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, and BHR-4GRV2 1.04 and earlier routers allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.Show less
1Avm
1Fritzbox
May 6, 2026
May 29, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.
1Goautodial
1Goadmin Ce
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arbitrary commands via the $type portion of the PATH_INFO.
1Goautodial
1Goadmin Ce
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arbitrary commands via the $action portion of the PATH_INFO.
1Cisco
1Secure Desktop
May 6, 2026
Apr 17, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CSCup83001.
1Arubanetworks
1Arubaos
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via un...Show more
The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.Show less
1Emc
1Secure Remote Services
May 6, 2026
Mar 12, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
1Network Vision
1Intravue
May 6, 2026
Feb 27, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Network Vision IntraVue before 2.3.0a14 on Windows allows remote attackers to execute arbitrary OS commands via unspecified vectors.
1Asus
10Rt Ac56s
Rt Ac56s FirmwareRt Ac68u+7 more
May 6, 2026
Feb 1, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmw...Show more
ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earlier, and RT-N56U routers with firmware 3.0.0.4.376.3715 and earlier allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.Show less
1Softaculous
1Webuzo
May 6, 2026
Dec 27, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.
1Fujitsu
4Arrows Kiss F 03d
Arrows Tab Lte F 01dF 12c+1 more
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute arbitrary commands via unspecified vectors.
1Advantech
2Eki 6340
Eki 6340 Firmware
May 6, 2026
Nov 20, 2014
N/A· v4
N/A· v3
9.0 HIGH· v2
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.
1Wp Dbmanager Project
1Wp Dbmanager
May 6, 2026
Oct 31, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" fie...Show more
The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup['mysqldumppath'] variable.Show less
1Gopro
2Gopro Hero
Gopro Hero Firmware
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.
1Cyberoam
1Cyberoam Os
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
9.0 HIGH· v2
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) cc...Show more
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.Show less
1Brocade
2Vyatta 5400 Vrouter
Vyatta 5400 Vrouter Software
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
9.0 HIGH· v2
The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters in a console command.
1Ibm
5Security Access Manager For Mobile 8.0 Firmware
Security Access Manager For Mobile ApplianceSecurity Access Manager For Web 7.0 Firmware+2 more
May 6, 2026
Oct 3, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remot...Show more
The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified vectors.Show less
1Gnu
1Bash
Apr 22, 2026
Sep 30, 2014
N/A· v4
8.8 HIGH· v3
10.0 HIGH· v2
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated...Show more
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.Show less
1Gnu
1Bash
May 6, 2026
Sep 27, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized mem...Show more
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.Show less