CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,259 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 86 of 126
- CVE-2024-54025MEDIUMCVSS 6.7EG 6.72025-04-08
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a privileged attacker to execute unauthorized code or commands v…
- CVE-2024-5403HIGHCVSS 7.2EG 7.22024-05-27
ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with administrator privilege to execute arbitrary system commands on the remote server.
- CVE-2024-54082HIGHCVSS 7.2EG 7.22024-12-23
home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed with the root privilege by an administrative user.
- CVE-2024-5411HIGHCVSS 8.8EG 8.82024-05-28
Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below.
- CVE-2024-54181HIGHCVSS 7.2EG 7.22024-12-30
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code…
- CVE-2024-5421HIGHCVSS 8.7EG 8.72024-06-04
Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.…
- CVE-2024-5461HIGHCVSS 8.0EG 8.02025-02-15
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform …
- CVE-2024-55020CRITICALCVSS 9.8EG 9.82026-03-03
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.
- CVE-2024-55021HIGHCVSS 7.5EG 7.52026-03-03
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.
- CVE-2024-55590HIGHCVSS 8.8EG 8.82025-03-11
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only adm…
- CVE-2024-5585HIGHCVSS 7.7EG 7.72024-06-09
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to…
- CVE-2024-55904HIGHCVSS 7.2EG 7.22025-02-14
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute a…
- CVE-2024-56132HIGHCVSS 8.4EG 8.42025-02-05
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) …
- CVE-2024-56137MEDIUMCVSS 6.8EG 6.82025-01-02
MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). Prior to version 1.9.0, a remote command execution vulnerabili…
- CVE-2024-56497MEDIUMCVSS 6.7EG 6.72025-01-14
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 throug…
- CVE-2024-5670CRITICALCVSS 9.8EG 9.82024-07-29
The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the remote server.
- CVE-2024-5672HIGHCVSS 7.2EG 7.22024-07-03
A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.
- CVE-2024-56808HIGHCVSS 7.8EG 7.82026-02-11
A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We…
- CVE-2024-57011CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.
- CVE-2024-57012CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.
- CVE-2024-57013CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.
- CVE-2024-57014CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg.
- CVE-2024-57015CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.
- CVE-2024-57016CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg.
- CVE-2024-57017CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.
- CVE-2024-57018CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.
- CVE-2024-57019CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg.
- CVE-2024-57020CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiScheduleCfg.
- CVE-2024-57021CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg.
- CVE-2024-57022CRITICALCVSS 8.8EG 9.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleCfg.
- CVE-2024-57023MEDIUMCVSS 6.8EG 6.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
- CVE-2024-57024MEDIUMCVSS 6.8EG 6.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg.
- CVE-2024-57025MEDIUMCVSS 6.8EG 6.82025-01-15
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg.
- CVE-2024-5717HIGHCVSS 8.8EG 8.82024-11-22
Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authenticati…
- CVE-2024-5719HIGHCVSS 8.8EG 8.82024-11-22
Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authenticati…
- CVE-2024-5720HIGHCVSS 8.8EG 8.82024-11-22
Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authenticati…
- CVE-2024-57357HIGHCVSS 8.0EG 8.02025-02-07
An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code via function sub_4256CC, which allows command injection by injecting 'devpwd'.
- CVE-2024-57542HIGHCVSS 8.8EG 8.82025-01-21
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.
- CVE-2024-57595CRITICALCVSS 9.8EG 9.82025-01-27
DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi bi…
- CVE-2024-57687CRITICALCVSS 9.8EG 9.82025-01-10
An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" GET request parameter.
- CVE-2024-5785HIGHCVSS 8.0EG 8.02024-06-10
Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenticated user to execute commands inside the router by making a POST request to the URL “/b…
- CVE-2024-58255MEDIUMCVSS 5.0EG 5.02025-08-08
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.
- CVE-2024-58256MEDIUMCVSS 4.5EG 4.52025-08-08
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.
- CVE-2024-58257MEDIUMCVSS 5.7EG 5.72025-08-08
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.
- CVE-2024-58274HIGHCVSS 8.3EG 8.32025-10-22
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.
- CVE-2024-58278HIGHCVSS 8.5EG 8.52025-12-04
perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allo…
- CVE-2024-58286CRITICALCVSS 9.3EG 9.32025-12-11
dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files…
- CVE-2024-58287HIGHCVSS 8.8EG 8.82025-12-11
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious b…
- CVE-2024-58294HIGHCVSS 8.7EG 8.82025-12-11
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting ma…
- CVE-2024-58314HIGHCVSS 8.8EG 8.82025-12-12
Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands thr…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →