CWE-78
6,626 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,626)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Alliedtelesis 8At Rg634a At Rg634a FirmwareImg616lh+5 moreMay 6, 2026 Mar 31, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary...Show more |
1Ibm 1Lotus Protector For Mail Security May 6, 2026 Mar 25, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors. |
1Ibm 1Lotus Protector For Mail Security May 6, 2026 Mar 25, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors. |
1Sophos 2Web Appliance Web Appliance FirmwareMay 6, 2026 Mar 18, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation variable in a customize...Show more |
delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metac...Show more |
TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to internet/ipv6.asp; (2) remote port to adm/management.asp; (3) pptp user...Show more |
1Thecus 2N8800 Nas Server N8800 Nas Server FirmwareApr 29, 2026 Jan 24, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid action with shell metacharacters in the username parameter. |
1Cisco 6Rvs4000 Rvs4000 FirmwareWap4410n+3 moreApr 29, 2026 Jan 12, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read cr...Show more |
1Cru Inc 2Ditto Forensic Fieldstation Ditto Forensic Fieldstation FirmwareApr 29, 2026 Jan 7, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task...Show more |
1Dlink 15Dsr 1000 Dsr 1000 FirmwareDsr 1000n+12 moreApr 29, 2026 Dec 19, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and D...Show more |
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML element. NOTE: this issue can be combined wi...Show more |
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in a (1) TestFile XML element or the (2) hostname. NOTE: this issue can b...Show more |
The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation. |
1Cisco 1Identity Services Engine Software Apr 29, 2026 Oct 25, 2013 N/A· v4 N/A· v3 9.0 HIGH· v2 The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.89...Show more |
1Draytek 2Vigor 2700 Router Vigor 2700 Router FirmwareApr 29, 2026 Oct 22, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWle...Show more |
The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary operating-system commands via crafted parameters to a file-related command, aka Bug ID...Show more |
1Tp Link 5Lm Firmware Tl Sc3130Tl Sc3130g+2 moreApr 29, 2026 Oct 11, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shel...Show more |
Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in unspecified command parameters, aka Bug IDs CSCtf19827 and CSCtf27788. |
1Cisco 1Prime Data Center Network Manager Apr 29, 2026 Sep 23, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka...Show more |
The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument. |