← Back
CWE-78

5,895 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (5,895)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Feb 27, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of the Modbus command tool in the debug route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Feb 27, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state whic...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state which is later processed during system setup, enabling remote code execution.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Feb 27, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Feb 27, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in the API V1 route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Feb 27, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname configuration which is later processed during system setup, resulting in remote code execution.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Mar 9, 2026
Feb 27, 2026
N/A· v4
6.6 MEDIUM· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via t...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Mar 9, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to t...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 4, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices fiel...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Mar 9, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argume...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argument fields within requests sent to the utility route, leading to remote code execution.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Mar 9, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update apply action.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Mar 9, 2026
Feb 27, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries inst...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Mar 9, 2026
Feb 27, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the firmware update route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Feb 27, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body s...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 4, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update action to achieve remote code execution.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Feb 27, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filenam...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Feb 27, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.Show less
1Jmpsec
1Osctrl
Feb 28, 2026
Feb 26, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An authenticated administrator can inject arbitrary shell co...Show more
osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An authenticated administrator can inject arbitrary shell commands via the hostname parameter when creating or editing environments. These commands are embedded into enrollment one-liner scripts generated using Go's `text/template` package (which does not perform shell escaping) and execute on every endpoint that enrolls using the compromised environment. An attacker with administrator access can achieve remote code execution on every endpoint that enrolls using the compromised environment. Commands execute as root/SYSTEM (the privilege level used for osquery enrollment) before osquery is installed, leaving no agent-level audit trail. This enables backdoor installation, credential exfiltration, and full endpoint compromise. This is fixed in osctrl `v0.5.0`. As a workaround, restrict osctrl administrator access to trusted personnel, review existing environment configurations for suspicious hostnames, and/or monitor enrollment scripts for unexpected commands.Show less
1Accellion
1Kiteworks
Mar 3, 2026
Feb 26, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could...Show more
Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a patch.Show less
2Z Libs
Zenc Lang
2Zen C
Zen C
May 1, 2026
Feb 26, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shel...Show more
Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shell commands by providing a specially crafted output filename via the `-o` command-line argument. The vulnerability existed in the `main` application logic (specifically in `src/main.c`), where the compiler constructed a shell command string to invoke the backend C compiler. This command string was built by concatenating various arguments, including the user-controlled output filename, and was subsequently executed using the `system()` function. Because `system()` invokes a shell to parse and execute the command, shell metacharacters within the output filename were interpreted by the shell, leading to arbitrary command execution. An attacker who can influence the command-line arguments passed to the `zc` compiler (like through a build script or a CI/CD pipeline configuration) can execute arbitrary commands with the privileges of the user running the compiler. The vulnerability has been fixed in version 0.4.2 by removing `system()` calls, implementing `ArgList`, and internal argument handling. Users are advised to update to Zen C version v0.4.2 or later.Show less
1Linuxfoundation
1Vitess
Mar 2, 2026
Feb 26, 2026
8.4 HIGH· v4
9.9 CRITICAL· v3
N/A· v2
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest...Show more
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that backup is restored. This can be used to provide that attacker with unintended/unauthorized access to the production deployment environment — allowing them to access information available in that environment as well as run any additional arbitrary commands there. Versions 23.0.3 and 22.0.4 contain a patch. Some workarounds are available. Those who intended to use an external decompressor then can always specify that decompressor command in the `--external-decompressor` flag value for `vttablet` and `vtbackup`. That then overrides any value specified in the manifest file. Those who did not intend to use an external decompressor, nor an internal one, can specify a value such as `cat` or `tee` in the `--external-decompressor` flag value for `vttablet` and `vtbackup` to ensure that a harmless command is always used.Show less