CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,261 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 31 of 126
- CVE-2020-21935CRITICALCVSS 9.8EG 9.82021-07-21
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.
- CVE-2020-21937CRITICALCVSS 9.8EG 9.82021-07-21
An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands.
- CVE-2020-21992HIGHCVSS 8.8EG 8.82021-04-29
Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called with the 'testemail' module through web.…
- CVE-2020-21999HIGHCVSS 8.8EG 8.82021-05-04
iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strIn…
- CVE-2020-2200HIGHCVSS 8.8EG 8.82020-06-03
Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoint, resulting in an OS command injection vulnerability exploitable by users able to store s…
- CVE-2020-22000HIGHCVSS 8.0EG 8.02021-04-27
HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a CSRF vulnerability to execute arbitrary shell commands as the web user via the 'set_comman…
- CVE-2020-22345HIGHCVSS 8.8EG 8.82021-08-18
/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.
- CVE-2020-2261HIGHCVSS 8.8EG 8.82020-09-16
Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller
- CVE-2020-22724CRITICALCVSS 9.8EG 9.82021-10-14
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
- CVE-2020-2276HIGHCVSS 8.8EG 8.82020-09-16
Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure permission to execute an arbitrary system command on the Jenkins controller as the OS user th…
- CVE-2020-23151CRITICALCVSS 9.8EG 9.82021-08-09
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
- CVE-2020-23256CRITICALCVSS 9.8EG 9.82023-01-20
An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electerms service.
- CVE-2020-23826HIGHCVSS 8.8EG 8.82021-01-26
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176
- CVE-2020-23934HIGHCVSS 8.8EG 8.82020-08-18
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.
- CVE-2020-24032CRITICALCVSS 9.8EG 9.82020-08-18
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.
- CVE-2020-24054CRITICALCVSS 9.8EG 9.82020-08-21
The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is t…
- CVE-2020-24057HIGHCVSS 8.8EG 8.82020-08-21
The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filtering on the unit. This endpoint is vulnerable to a command injection. An authenticated at…
- CVE-2020-24220HIGHCVSS 8.8EG 8.82020-08-17
ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the server.
- CVE-2020-24297HIGHCVSS 8.8EG 8.82020-11-18
httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST requests to the endpoint /admin/powerline. Fixed version: TL-WPA4220(EU)_V4_201023
- CVE-2020-24354HIGHCVSS 8.8EG 8.82020-08-31
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.
- CVE-2020-24365HIGHCVSS 8.8EG 8.82020-09-24
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed…
- CVE-2020-24552MEDIUMCVSS 5.5EG 5.52020-09-10
Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code and execute system commands without pri…
- CVE-2020-24572HIGHCVSS 8.8EG 8.82020-08-24
An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack the underlying OS (Raspberry Pi) running this software, and…
- CVE-2020-24581HIGHCVSS 8.0EG 8.02020-12-22
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating Sys…
- CVE-2020-24635HIGHCVSS 7.2EG 7.22021-03-29
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8…
- CVE-2020-24636CRITICALCVSS 9.8EG 9.82021-03-29
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8…
- CVE-2020-24719CRITICALCVSS 9.8EG 9.82020-11-12
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the magic cookie is included in the content of …
- CVE-2020-24849HIGHCVSS 8.8EG 8.82020-11-05
A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remote code execution b…
- CVE-2020-24899HIGHCVSS 8.8EG 8.82021-02-15
Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp query.
- CVE-2020-2490HIGHCVSS 7.2EG 7.22020-11-16
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
- CVE-2020-24916CRITICALCVSS 9.8EG 9.82020-09-09
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
- CVE-2020-2492HIGHCVSS 7.2EG 7.22020-11-16
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
- CVE-2020-25036HIGHCVSS 8.8EG 8.82021-02-02
UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected less command.
- CVE-2020-2507CRITICALCVSS 9.8EG 9.82021-02-03
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prio…
- CVE-2020-2508HIGHCVSS 7.2EG 7.22021-01-11
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in th…
- CVE-2020-2509CRITICALCVSS 9.8EG 9.8⚠ KEV2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the …
- CVE-2020-25094CRITICALCVSS 9.8EG 9.82020-12-17
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent insta…
- CVE-2020-25206HIGHCVSS 7.2EG 7.22021-07-20
The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute opera…
- CVE-2020-25223CRITICALCVSS 9.8EG 9.8⚠ KEV2020-09-25
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
- CVE-2020-25367CRITICALCVSS 9.8EG 9.82021-11-04
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
- CVE-2020-25368CRITICALCVSS 9.8EG 9.82021-11-04
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
- CVE-2020-25494CRITICALCVSS 9.8EG 9.82020-12-18
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.
- CVE-2020-25499HIGHCVSS 8.8EG 8.82020-12-09
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
- CVE-2020-25506CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-02
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
- CVE-2020-25560CRITICALCVSS 9.8EG 9.82021-08-11
In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands on “ping”, “…
- CVE-2020-25618HIGHCVSS 8.8EG 8.82020-12-16
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges i…
- CVE-2020-25755HIGHCVSS 8.8EG 8.82021-06-16
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to execute arbitrary commands via the force parameter.
- CVE-2020-25757HIGHCVSS 8.8EG 8.82020-12-15
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DS…
- CVE-2020-25759HIGHCVSS 8.8EG 8.82020-12-15
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided …
- CVE-2020-25765CRITICALCVSS 9.8EG 9.82020-10-27
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140.
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →