CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,259 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 23 of 126
- CVE-2019-17508CRITICALCVSS 9.8EG 9.82019-10-11
On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.
- CVE-2019-17509CRITICALCVSS 9.8EG 9.82019-10-11
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetMasterWLanSettings with shell metacharacters to /squashfs-root/www/…
- CVE-2019-17510CRITICALCVSS 9.8EG 9.82019-10-11
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell metacharacters to /squashfs-root/www/HNAP1/…
- CVE-2019-17526CRITICALCVSS 9.8EG 9.82019-10-18
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating syst…
- CVE-2019-17621CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-30
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP serv…
- CVE-2019-17625CRITICALCVSS 9.0EG 9.02019-10-16
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This al…
- CVE-2019-17642HIGHCVSS 8.8EG 8.82020-03-05
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscov…
- CVE-2019-17650HIGHCVSS 7.8EG 7.82019-11-21
An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by by…
- CVE-2019-1767MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This co…
- CVE-2019-1768MEDIUMCVSS 6.7EG 6.72019-05-16
A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection. This co…
- CVE-2019-1769MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system of an attached line card with the privile…
- CVE-2019-1770MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vul…
- CVE-2019-1774MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of…
- CVE-2019-1775MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of…
- CVE-2019-1776MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerability is due to insufficient…
- CVE-2019-1778MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with the privilege level of root. The vulnerability is due to insufficie…
- CVE-2019-18182CRITICALCVSS 9.8EG 9.82020-02-24
pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default …
- CVE-2019-18183CRITICALCVSS 9.8EG 9.82020-02-24
pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable the non-default…
- CVE-2019-18184CRITICALCVSS 9.8EG 9.82019-11-27
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
- CVE-2019-1829MEDIUMCVSS 6.7EG 6.72019-04-18
A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication. The attacker would need val…
- CVE-2019-18370CRITICALCVSS 9.8EG 9.82019-10-23
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the …
- CVE-2019-1839MEDIUMCVSS 6.7EG 6.72019-08-21
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected so…
- CVE-2019-18396HIGHCVSS 7.2EG 7.22019-10-31
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS comm…
- CVE-2019-18424MEDIUMCVSS 6.8EG 6.82019-10-31
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host m…
- CVE-2019-1850HIGHCVSS 7.2EG 7.22019-08-21
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected…
- CVE-2019-1864HIGHCVSS 8.8EG 8.82019-08-21
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected…
- CVE-2019-1865HIGHCVSS 8.8EG 8.82019-08-21
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected…
- CVE-2019-1878HIGHCVSS 7.5EG 8.82019-06-20
A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, adjacent attacker to inject arbitrary shell commands that a…
- CVE-2019-1879MEDIUMCVSS 6.4EG 6.72019-06-20
A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient validatio…
- CVE-2019-1883HIGHCVSS 7.8EG 7.82019-08-21
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privile…
- CVE-2019-18830CRITICALCVSS 9.8EG 9.82019-12-16
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vuln…
- CVE-2019-18839CRITICALCVSS 9.0EG 9.02019-11-13
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user informati…
- CVE-2019-1885HIGHCVSS 7.2EG 7.22019-08-21
A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device. The vulnerability is…
- CVE-2019-18873CRITICALCVSS 9.0EG 9.02019-11-12
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user informatio…
- CVE-2019-18894HIGHCVSS 7.8EG 7.82020-01-13
In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to support Bank Mode functionality. A flaw in the processing of a command allows execution of …
- CVE-2019-18909HIGHCVSS 8.0EG 8.02019-11-22
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.
- CVE-2019-18910MEDIUMCVSS 6.8EG 6.82019-11-22
The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.
- CVE-2019-1893HIGHCVSS 7.8EG 7.82019-07-06
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. The vulnerability is …
- CVE-2019-18934HIGHCVSS 7.3EG 7.32019-11-19
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` suppo…
- CVE-2019-1896HIGHCVSS 7.2EG 7.22019-08-21
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insuff…
- CVE-2019-19034HIGHCVSS 7.2EG 7.22020-03-23
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands…
- CVE-2019-19041HIGHCVSS 7.2EG 7.22019-11-17
An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgrade package before processing it. As a result, official upgrade packages can be modified t…
- CVE-2019-19117HIGHCVSS 8.8EG 8.82019-11-18
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.
- CVE-2019-19148CRITICALCVSS 9.8EG 9.82020-03-20
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.
- CVE-2019-19217HIGHCVSS 8.8EG 8.82020-04-30
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.
- CVE-2019-19220HIGHCVSS 8.8EG 8.82020-04-30
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
- CVE-2019-19356CRITICALCVSS 7.5EG 9.0⚠ KEV2020-02-07
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it…
- CVE-2019-19469HIGHCVSS 8.8EG 8.82019-12-01
In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.
- CVE-2019-19487HIGHCVSS 8.8EG 8.82020-03-20
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
- CVE-2019-19509CRITICALCVSS 8.8EG 9.02020-01-06
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which …
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →