CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,257 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 11 of 126
- CVE-2018-0341HIGHCVSS 8.8EG 8.82018-07-16
A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authenticated, remote attacker to perform a command injection and execute commands with the privile…
- CVE-2018-0348HIGHCVSS 7.2EG 7.22018-07-18
A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attack…
- CVE-2018-0349CRITICALCVSS 9.8EG 9.82018-07-18
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the …
- CVE-2018-0424HIGHCVSS 8.8EG 8.82018-10-05
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to ex…
- CVE-2018-0427HIGHCVSS 8.8EG 8.82018-08-15
A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to incorrect input validation of …
- CVE-2018-0432HIGHCVSS 8.8EG 8.82018-10-05
A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain…
- CVE-2018-0433HIGHCVSS 7.8EG 7.82018-10-05
A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient inp…
- CVE-2018-0453HIGHCVSS 8.2EG 8.22018-10-05
A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with…
- CVE-2018-0477MEDIUMCVSS 6.7EG 6.72018-10-05
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affec…
- CVE-2018-0481MEDIUMCVSS 6.7EG 6.72018-10-05
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affec…
- CVE-2018-0506CRITICALCVSS 9.8EG 9.82018-01-26
Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0512MEDIUMCVSS 6.8EG 6.82018-02-08
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0514CRITICALCVSS 9.8EG 9.82018-02-08
MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0523HIGHCVSS 8.8EG 8.82018-03-09
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0539CRITICALCVSS 9.8EG 9.82018-03-22
QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors.
- CVE-2018-0545CRITICALCVSS 9.8EG 9.82018-04-09
LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0556HIGHCVSS 8.8EG 8.82018-04-09
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0569HIGHCVSS 8.8EG 8.82018-06-26
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0625HIGHCVSS 7.2EG 7.22019-01-09
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.
- CVE-2018-0626HIGHCVSS 7.2EG 7.22019-01-09
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.
- CVE-2018-0627HIGHCVSS 7.2EG 7.22019-01-09
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.
- CVE-2018-0628HIGHCVSS 7.2EG 7.22019-01-09
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
- CVE-2018-0629HIGHCVSS 7.2EG 7.22019-01-09
Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
- CVE-2018-0630HIGHCVSS 7.2EG 7.22019-01-09
Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd parameter.
- CVE-2018-0631HIGHCVSS 7.2EG 7.22019-01-09
Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.
- CVE-2018-0634HIGHCVSS 7.2EG 7.22019-01-09
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmode parameter of a certain URL.
- CVE-2018-0635HIGHCVSS 7.2EG 7.22019-01-09
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.
- CVE-2018-0636HIGHCVSS 7.2EG 7.22019-01-09
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.
- CVE-2018-0637HIGHCVSS 7.2EG 7.22019-01-09
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameter.
- CVE-2018-0638HIGHCVSS 7.2EG 7.22019-01-09
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.
- CVE-2018-0639HIGHCVSS 7.2EG 7.22019-01-09
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.
- CVE-2018-0643MEDIUMCVSS 6.6EG 6.62018-09-07
Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0677MEDIUMCVSS 6.8EG 6.82019-01-09
BN-SDWBP3 firmware version 1.0.9 and earlier allows attacker with administrator rights on the same network segment to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0694CRITICALCVSS 9.8EG 9.82018-11-15
FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2018-0707HIGHCVSS 7.2EG 8.22018-07-17
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
- CVE-2018-0708HIGHCVSS 8.8EG 8.82018-07-17
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
- CVE-2018-0709HIGHCVSS 8.8EG 8.82018-07-17
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
- CVE-2018-0710HIGHCVSS 8.8EG 8.82018-07-17
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
- CVE-2018-1000006CRITICALCVSS 8.8EG 9.02018-01-24
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can b…
- CVE-2018-1000019HIGHCVSS 8.8EG 8.82018-02-09
OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role. This vulnerability appears to have been fixed in 5.0.0 Patch 2 or h…
- CVE-2018-1000042CRITICALCVSS 9.8EG 9.82018-02-09
Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS C…
- CVE-2018-1000043CRITICALCVSS 9.8EG 9.82018-02-09
Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS C…
- CVE-2018-1000118HIGHCVSS 8.8EG 8.82018-03-07
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol h…
- CVE-2018-1000666CRITICALCVSS 9.8EG 9.82018-09-06
GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in method: noti…
- CVE-2018-1000885CRITICALCVSS 9.8EG 9.82018-12-20
PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in function pgp_exec() phkp.php:98 that can result in It is…
- CVE-2018-10354HIGHCVSS 8.8EG 8.82018-05-23
A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. Authentication …
- CVE-2018-10431HIGHCVSS 7.2EG 7.22018-04-26
D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.
- CVE-2018-10562CRITICALCVSS 9.8EG 9.8⚠ KEV2018-05-04
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the …
- CVE-2018-10587HIGHCVSS 7.2EG 7.22018-11-01
NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow remote authenticated attackers to inject arbitrary code, resulting in remote code execution.
- CVE-2018-10660CRITICALCVSS 9.8EG 9.82018-06-26
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →