CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,262 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 38 of 126
- CVE-2021-1401HIGHCVSS 8.8EG 8.82021-05-06
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arb…
- CVE-2021-1421HIGHCVSS 7.8EG 7.82021-05-06
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to perform a command injection attack on an affected device. The vulnerability is due to insufficient validation of user-s…
- CVE-2021-1441MEDIUMCVSS 6.7EG 6.72021-03-24
A vulnerability in the hardware initialization routines of Cisco IOS XE Software for Cisco 1100 Series Industrial Integrated Services Routers and Cisco ESR6300 Embedded Series Routers could allow an authenticated, local attacker to execute…
- CVE-2021-1443HIGHCVSS 5.5EG 7.22021-03-24
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because …
- CVE-2021-1448HIGHCVSS 7.8EG 7.82021-04-29
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is ru…
- CVE-2021-1452MEDIUMCVSS 6.8EG 6.82021-03-24
A vulnerability in the ROM Monitor (ROMMON) of Cisco IOS XE Software for Cisco Catalyst IE3200, IE3300, and IE3400 Rugged Series Switches, Cisco Catalyst IE3400 Heavy Duty Series Switches, and Cisco Embedded Services 3300 Series Switches c…
- CVE-2021-1473CRITICALCVSS 5.3EG 9.82021-04-08
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more in…
- CVE-2021-1476MEDIUMCVSS 6.7EG 6.72021-04-29
A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system …
- CVE-2021-1487HIGHCVSS 8.8EG 8.82021-05-22
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulne…
- CVE-2021-1488MEDIUMCVSS 6.7EG 6.72021-04-29
A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root p…
- CVE-2021-1497CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-06
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerab…
- CVE-2021-1498CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-06
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerab…
- CVE-2021-1514HIGHCVSS 7.8EG 7.82021-05-06
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Administrator privileges on the underlying operating system. This vulnerability is due to ins…
- CVE-2021-1529HIGHCVSS 7.8EG 7.82021-10-21
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An att…
- CVE-2021-1538MEDIUMCVSS 4.7EG 4.72021-06-04
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This vulnerability is due to insufficient sanitization of configurat…
- CVE-2021-1557MEDIUMCVSS 6.0EG 6.02021-05-22
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insuffici…
- CVE-2021-1558MEDIUMCVSS 6.0EG 6.02021-05-22
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insuffici…
- CVE-2021-1559MEDIUMCVSS 6.5EG 6.52021-05-22
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executi…
- CVE-2021-1560HIGHCVSS 6.5EG 7.22021-05-22
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executi…
- CVE-2021-1580HIGHCVSS 6.5EG 7.22021-08-25
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected sys…
- CVE-2021-1584MEDIUMCVSS 6.0EG 6.02021-08-25
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient…
- CVE-2021-1594HIGHCVSS 7.5EG 8.12021-10-06
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input v…
- CVE-2021-1602HIGHCVSS 8.2EG 8.22021-08-04
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating sy…
- CVE-2021-1618HIGHCVSS 6.5EG 7.22021-07-22
Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnera…
- CVE-2021-20017HIGHCVSS 8.8EG 8.82021-03-13
A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
- CVE-2021-20026HIGHCVSS 8.8EG 8.82021-05-27
A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.
- CVE-2021-20035CRITICALCVSS 6.5EG 9.0⚠ KEV2021-09-27
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
- CVE-2021-20039CRITICALCVSS 8.8EG 9.02021-12-08
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200…
- CVE-2021-20044HIGHCVSS 8.8EG 8.82021-12-08
A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
- CVE-2021-20074HIGHCVSS 8.8EG 8.82021-02-16
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.
- CVE-2021-20122HIGHCVSS 7.2EG 7.22021-10-11
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker connected to the router's LAN and authenti…
- CVE-2021-20138HIGHCVSS 8.8EG 8.82021-12-09
An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same network can execute commands as root on the …
- CVE-2021-20139HIGHCVSS 8.8EG 8.82021-12-09
An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on th…
- CVE-2021-20140HIGHCVSS 8.8EG 8.82021-12-09
An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on t…
- CVE-2021-20141HIGHCVSS 8.8EG 8.82021-12-09
An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on t…
- CVE-2021-20142HIGHCVSS 8.8EG 8.82021-12-09
An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on t…
- CVE-2021-20143HIGHCVSS 8.8EG 8.82021-12-09
An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on t…
- CVE-2021-20144HIGHCVSS 8.8EG 8.82021-12-09
An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on t…
- CVE-2021-20159HIGHCVSS 8.8EG 8.82021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command injection as root by supplying a malformed parameter.
- CVE-2021-20160HIGHCVSS 8.8EG 8.82021-12-30
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the device is vulnerable to command injection …
- CVE-2021-20173HIGHCVSS 8.8EG 8.82021-12-30
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via prec…
- CVE-2021-20557HIGHCVSS 7.2EG 7.22021-05-24
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184.
- CVE-2021-20638MEDIUMCVSS 6.8EG 6.82021-02-12
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
- CVE-2021-20639MEDIUMCVSS 6.8EG 6.82021-02-12
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
- CVE-2021-20648MEDIUMCVSS 6.8EG 6.82021-02-12
ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
- CVE-2021-20655HIGHCVSS 7.2EG 7.22021-02-17
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
- CVE-2021-20658CRITICALCVSS 9.8EG 9.82021-02-24
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
- CVE-2021-20682HIGHCVSS 7.2EG 7.22021-03-26
baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS commands via unspecified vectors.
- CVE-2021-20696HIGHCVSS 8.8EG 8.82021-04-26
DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted request to a specific CGI program.
- CVE-2021-20708HIGHCVSS 7.2EG 7.22021-04-26
NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier) allow authenticated attackers to execute arbitrary OS commands by sending a sp…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →