← Back
CWE-78

6,626 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,626)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linksys
1Wvbr0 Firmware
May 13, 2026
Dec 21, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web man...Show more
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.Show less
1Cambiumnetworks
2Epmp 1000 Firmware
Epmp 2000 Firmware
May 13, 2026
Dec 20, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly us...Show more
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.Show less
1Zoom
1Zoom
May 13, 2026
Dec 19, 2017
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging t...Show more
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.Show less
1Tp Link
15Tl War1200l Firmware
Tl War1300l FirmwareTl War1750l Firmware+12 more
May 13, 2026
Dec 19, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_by...Show more
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in uhttpd.Show less
1Tp Link
15Tl War1200l Firmware
Tl War1300l FirmwareTl War1750l Firmware+12 more
May 13, 2026
Dec 19, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif...Show more
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd.Show less
1Zivif
1Pr115 204 P Rs Firmware
May 13, 2026
Dec 19, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demo...Show more
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="1504225666237"&-url=$(reboot) request.Show less
2Heketi Project
Redhat
2Enterprise Linux
Heketi
May 13, 2026
Dec 18, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as...Show more
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege escalation.Show less
1Qt
1Qt
May 13, 2026
Dec 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
3Debian
RedhatRuby Lang
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
May 13, 2026
Dec 15, 2017
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe...Show more
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution.Show less
2Debian
Otrs
2Debian Linux
Otrs
May 13, 2026
Dec 8, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) a...Show more
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.Show less
2Debian
Mercurial
2Debian Linux
Mercurial
May 13, 2026
Dec 7, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use...Show more
In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.Show less
1Articatech
1Artica Proxy
May 13, 2026
Dec 7, 2017
N/A· v4
9.0 CRITICAL· v3
8.5 HIGH· v2
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.
1Debian
1Most
May 13, 2026
Dec 5, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell metacharacters in the...Show more
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell metacharacters in the name of an LZMA-compressed file.Show less
1Princeton
1Ptw Wms1 Firmware
May 13, 2026
Dec 1, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
1Gnome
1Evince
May 13, 2026
Nov 27, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
1Gitphp Project
1Gitphp
May 13, 2026
Nov 27, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GitPHP by xiphux is vulnerable to OS Command Injections
1Tp Link
54Tl Er3210g Firmware
Tl Er3220g FirmwareTl Er5110g Firmware+51 more
May 13, 2026
Nov 27, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the...Show more
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.Show less
1Tp Link
51Tl Er3210g Firmware
Tl Er3220g FirmwareTl Er5110g Firmware+48 more
May 13, 2026
Nov 27, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get...Show more
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd.Show less
1Tp Link
51Tl Er3210g Firmware
Tl Er3220g FirmwareTl Er5110g Firmware+48 more
May 13, 2026
Nov 27, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zo...Show more
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd.Show less
1Dbltek
1Web Server
May 13, 2026
Nov 24, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Ba...Show more
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp request, which supports a "<%%25call system.exec:" string in the passwd parameter.Show less