CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,263 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 53 of 126
- CVE-2022-28171CRITICALCVSS 7.5EG 9.82022-06-27
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending mess…
- CVE-2022-28373CRITICALCVSS 9.8EG 9.82022-07-14
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of the crtcrpc JSON listener in /usr/lib/lua/luci/crtc.lua. A remote attacker on the local netw…
- CVE-2022-28374HIGHCVSS 8.8EG 8.82022-07-14
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An authenticated remote attacker on the local network can inje…
- CVE-2022-28375CRITICALCVSS 9.8EG 9.82022-07-14
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metac…
- CVE-2022-28491CRITICALCVSS 9.8EG 9.82023-03-23
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
- CVE-2022-28494CRITICALCVSS 9.8EG 9.82023-03-23
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a craf…
- CVE-2022-28495CRITICALCVSS 9.8EG 9.82023-03-24
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a c…
- CVE-2022-28557CRITICALCVSS 9.8EG 9.82022-05-04
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command exec…
- CVE-2022-28571CRITICALCVSS 9.8EG 9.82022-05-02
D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.
- CVE-2022-28572HIGHCVSS 8.8EG 8.82022-05-02
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function
- CVE-2022-28573CRITICALCVSS 9.8EG 9.82022-05-02
D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows attackers to execute arbitrary commands via the system_time_timezone parameter.
- CVE-2022-28575CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed paylo…
- CVE-2022-28577CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payloa…
- CVE-2022-28578CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- CVE-2022-28579CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payloa…
- CVE-2022-28580CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payloa…
- CVE-2022-28581CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payl…
- CVE-2022-28582CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payloa…
- CVE-2022-28583CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- CVE-2022-28584CRITICALCVSS 9.8EG 9.82022-05-05
It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.
- CVE-2022-28810CRITICALCVSS 6.8EG 9.0⚠ KEV2022-04-18
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator passwor…
- CVE-2022-28811CRITICALCVSS 9.8EG 9.82022-09-28
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.
- CVE-2022-2884CRITICALCVSS 9.9EG 9.92022-10-17
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint
- CVE-2022-28888CRITICALCVSS 9.8EG 9.82022-07-13
Spryker Commerce OS 1.4.2 allows Remote Command Execution.
- CVE-2022-28895CRITICALCVSS 9.8EG 9.82022-05-10
A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.
- CVE-2022-28896CRITICALCVSS 9.8EG 9.82022-05-10
A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.
- CVE-2022-28901CRITICALCVSS 9.8EG 9.82022-05-10
A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.
- CVE-2022-28905CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parameter in /setting/setDeviceName.
- CVE-2022-28906CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.
- CVE-2022-28907CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.
- CVE-2022-28908CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in /setting/setDiagnosisCfg.
- CVE-2022-28909CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx parameter in /setting/setWebWlanIdx.
- CVE-2022-28910CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicename parameter in /setting/setDeviceName.
- CVE-2022-28911CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/CloudACMunualUpdate.
- CVE-2022-28912CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW.
- CVE-2022-28913CRITICALCVSS 9.8EG 9.82022-05-10
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUploadSetting.
- CVE-2022-28915CRITICALCVSS 9.8EG 9.82022-05-10
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.
- CVE-2022-29013CRITICALCVSS 9.8EG 9.82022-06-09
A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.
- CVE-2022-29061HIGHCVSS 7.2EG 7.22022-09-09
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted H…
- CVE-2022-29080CRITICALCVSS 9.8EG 9.82022-04-12
The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.
- CVE-2022-29256MEDIUMCVSS 6.5EG 6.52022-05-25
sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacke…
- CVE-2022-29303CRITICALCVSS 9.8EG 9.8⚠ KEV2022-05-12
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
- CVE-2022-29337CRITICALCVSS 9.8EG 9.82022-05-24
C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.
- CVE-2022-29472CRITICALCVSS 9.8EG 9.82022-10-25
An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution…
- CVE-2022-29516CRITICALCVSS 9.8EG 9.82022-05-18
The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(1100, 3200, 3500), IPCOM EX2 NW(1100, 3200, 3500), IPCOM EX2 DC, IPCOM EX2 DC, IPCOM EX IN(2300, 2500, 2700), IPCOM EX …
- CVE-2022-29520CRITICALCVSS 9.8EG 9.82022-10-25
An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send an XM…
- CVE-2022-29539CRITICALCVSS 9.8EG 9.82022-05-12
resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated att…
- CVE-2022-29583HIGHCVSS 7.8EG 7.82022-04-22
service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporte…
- CVE-2022-29592CRITICALCVSS 9.8EG 9.82022-05-05
Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).
- CVE-2022-29841HIGHCVSS 8.0EG 8.02023-05-10
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →