CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,738
Total CVEs
667
Critical
901
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 90
2 Totolink 85
3 Fortinet 58
4 Dell 58
5 Tp Link 36
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,738)

CVE-2025-10680
8.8

This vulnerability allows a malicious OpenVPN server to execute arbitrary shell commands on client systems when DNS configuration updates are enabled....

Oct 24, 2025
CVE-2025-6541
8.8

This vulnerability allows authenticated users of the web management interface to execute arbitrary operating system commands on affected Omada/Tp-Link...

Oct 21, 2025
CVE-2025-47901
8.8

This CVE describes an OS command injection vulnerability in Microchip Time Provider 4100 devices that allows attackers to execute arbitrary operating ...

Oct 20, 2025
CVE-2025-57457
8.8

This CVE describes an OS command injection vulnerability in the Curo UC300 admin panel where local attackers can execute arbitrary operating system co...

Oct 8, 2025
CVE-2025-54403
8.8

This CVE describes OS command injection vulnerabilities in Planet WGR-500 routers that allow remote attackers to execute arbitrary commands via specia...

Oct 7, 2025
CVE-2025-54404
8.8

This CVE describes OS command injection vulnerabilities in Planet WGR-500 routers that allow remote attackers to execute arbitrary commands via specia...

Oct 7, 2025
CVE-2025-54406
8.8

This CVE describes OS command injection vulnerabilities in Planet WGR-500 routers that allow remote attackers to execute arbitrary commands via specia...

Oct 7, 2025
CVE-2025-10589
8.8

This CVE describes an OS command injection vulnerability in N-Partner's N-Reporter, N-Cloud, and N-Probe products. Authenticated remote attackers can ...

Sep 17, 2025
CVE-2025-55211
8.8

CVE-2025-55211 allows authenticated FreePBX administrators to execute arbitrary shell commands by manipulating language settings in the framework modu...

Sep 15, 2025
CVE-2025-56413
8.8

This CVE describes an OS command injection vulnerability in 1panel's SSH operation function that allows attackers to execute arbitrary commands on the...

Sep 10, 2025
CVE-2005-10004
EPSS 54% 8.8

This vulnerability allows authenticated users to execute arbitrary shell commands on Cacti servers through improper input handling in the graph_view.p...

Aug 30, 2025
CVE-2025-8748
8.8

CVE-2025-8748 is a command injection vulnerability in MiR robot software that allows authenticated users to execute arbitrary operating system command...

Aug 8, 2025
CVE-2013-10050
EPSS 61.9% 8.8

This CVE describes an authenticated OS command injection vulnerability in multiple D-Link router models that allows attackers with valid credentials t...

Aug 1, 2025
CVE-2025-29534
8.8

An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows attackers with valid credentials to execut...

Jul 28, 2025
CVE-2025-41683
8.8

An authenticated remote attacker can execute arbitrary operating system commands with root privileges on affected devices by exploiting improper input...

Jul 23, 2025
CVE-2025-53376
8.8

CVE-2025-53376 is a command injection vulnerability in Dokploy that allows authenticated low-privileged users to execute arbitrary operating system co...

Jul 7, 2025
CVE-2025-34088
EPSS 49.7% 8.8

This vulnerability allows authenticated users in Pandora FMS to execute arbitrary operating system commands through the net_tools.php functionality. A...

Jul 3, 2025
CVE-2025-5459
8.8

This vulnerability allows authenticated users with node group editing permissions in Puppet Enterprise to execute arbitrary commands as root on the pr...

Jun 26, 2025
CVE-2025-41427
8.8

This vulnerability allows remote authenticated attackers to execute arbitrary operating system commands on affected WRC-X3000 series routers through t...

Jun 24, 2025
CVE-2025-34033
8.8

This CVE describes an OS command injection vulnerability in Blue Angel Software Suite's web interface that allows authenticated attackers to execute a...

Jun 24, 2025
CVE-2025-34024
8.8

An authenticated OS command injection vulnerability in Edimax EW-7438RPn firmware allows attackers to execute arbitrary commands as root via the mp.as...

Jun 20, 2025
CVE-2011-10007
8.8

This vulnerability in File::Find::Rule Perl module allows arbitrary command execution when processing malicious filenames. Attackers can execute syste...

Jun 5, 2025
CVE-2025-3883
8.8

This vulnerability allows attackers on the same network to execute arbitrary commands on eCharge Hardy Barth cPH2 charging stations without authentica...

May 22, 2025
CVE-2025-3881
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary commands on eCharge Hardy Barth cPH2 charging stations without authenticatio...

May 22, 2025
CVE-2025-24351
8.8

A remote authenticated attacker with low privileges can execute arbitrary operating system commands as root on affected ctrlX OS systems via crafted H...

Apr 30, 2025
CVE-2025-25053
8.8

This CVE describes an OS command injection vulnerability in the WEB UI setting page of Wi-Fi AP UNIT 'AC-WPS-11ac series' devices. If exploited, a rem...

Apr 9, 2025
CVE-2025-30004
EPSS 78.6% 8.8

Xorcom CompletePBX versions up to 5.2.35 contain an authenticated command injection vulnerability in the administrator Task Scheduler functionality. A...

Mar 31, 2025
CVE-2025-20138
8.8

This vulnerability in Cisco IOS XR Software allows an authenticated, low-privileged local attacker to execute arbitrary commands as root on the underl...

Mar 12, 2025
CVE-2024-55590
8.8

This vulnerability allows authenticated attackers with read-only admin permissions and CLI access to execute arbitrary operating system commands on Fo...

Mar 11, 2025
CVE-2024-52961
8.8

This CVE describes an OS command injection vulnerability in Fortinet FortiSandbox that allows authenticated users with read-only permissions to execut...

Mar 11, 2025
CVE-2025-1244
8.8

A command injection vulnerability in Emacs allows remote attackers to execute arbitrary shell commands on vulnerable systems by tricking users into vi...

Feb 12, 2025
CVE-2025-20029
EPSS 58.3% 8.8

This command injection vulnerability in F5 BIG-IP's iControl REST API and tmsh save command allows authenticated attackers to execute arbitrary system...

Feb 5, 2025
CVE-2024-40890
KEV EPSS 13% 8.8

This is a post-authentication command injection vulnerability in Zyxel VMG4325-B10A DSL CPE devices that allows authenticated attackers to execute arb...

Feb 4, 2025
CVE-2024-40891
KEV EPSS 39.3% 8.8

This is a post-authentication command injection vulnerability in Zyxel VMG4325-B10A DSL CPE devices. An authenticated attacker can execute arbitrary o...

Feb 4, 2025
CVE-2024-57542
8.8

The Linksys E8450 router firmware contains a command injection vulnerability in the email check functionality that allows authenticated attackers to e...

Jan 21, 2025
CVE-2025-0457
8.8

CVE-2025-0457 is an OS command injection vulnerability in NetVision Information's airPASS product that allows authenticated users with regular privile...

Jan 16, 2025
CVE-2024-57022
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...

Jan 15, 2025
CVE-2024-57012
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious payloads i...

Jan 15, 2025
CVE-2024-57013
8.8

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where attackers can execute arbitrary commands via the 'switch' pa...

Jan 15, 2025
CVE-2024-57014
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...

Jan 15, 2025
CVE-2024-57015
8.8

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where attackers can execute arbitrary commands via the 'hour' para...

Jan 15, 2025
CVE-2024-57016
8.8

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where an attacker can execute arbitrary commands via the 'user' pa...

Jan 15, 2025
CVE-2024-57017
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...

Jan 15, 2025
CVE-2024-57018
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...

Jan 15, 2025
CVE-2024-57019
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...

Jan 15, 2025
CVE-2024-57020
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...

Jan 15, 2025
CVE-2024-57021
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...

Jan 15, 2025
CVE-2024-57011
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands i...

Jan 15, 2025
CVE-2024-27778
8.8

This CVE-2024-27778 is an OS command injection vulnerability in Fortinet FortiSandbox that allows authenticated attackers with read-only permissions t...

Jan 14, 2025
CVE-2024-43649
8.8

Authenticated command injection in Iocharger AC charging station firmware allows attackers with low-privilege accounts to execute arbitrary commands a...

Jan 9, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,738 CVEs classified as CWE-78, with 667 rated critical and 901 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free