CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,812
Total CVEs
717
Critical
925
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 92
2 Totolink 85
3 Fortinet 58
4 Dell 58
5 Tp Link 37
6 Zyxel 34
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,812)

CVE-2023-44403
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. Attackers ca...

May 3, 2024
CVE-2023-42123
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Control Web Panel installations. Attack...

May 3, 2024
CVE-2023-42120
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Control Web Panel installations. The fl...

May 3, 2024
CVE-2023-41197
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. Attackers ca...

May 3, 2024
CVE-2023-41199
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. Attacker...

May 3, 2024
CVE-2023-41201
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...

May 3, 2024
CVE-2023-41191
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. The flaw...

May 3, 2024
CVE-2023-41193
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. Attacker...

May 3, 2024
CVE-2023-41195
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. Attacker...

May 3, 2024
CVE-2023-41189
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. Attacker...

May 3, 2024
CVE-2023-40479
8.8

This vulnerability allows attackers on the same local network to execute arbitrary commands with root privileges on NETGEAR RAX30 routers without auth...

May 3, 2024
CVE-2023-39471
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on TP-Link TL-WR841N routers without authentication. The fl...

May 3, 2024
CVE-2023-35723
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers without authentication. Attackers c...

May 3, 2024
CVE-2023-34279
8.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-2150 routers without authentication. The flaw exi...

May 3, 2024
CVE-2024-3193
8.8

This critical vulnerability in MailCleaner allows remote attackers to execute arbitrary operating system commands through admin endpoints. It affects ...

Apr 29, 2024
CVE-2024-20295
8.8

This vulnerability allows authenticated local attackers with read-only or higher privileges on Cisco Integrated Management Controller (IMC) devices to...

Apr 24, 2024
CVE-2023-4856
8.8

This format string vulnerability in Lenovo's SMM/SMM2 and FPC software allows authenticated users to execute arbitrary commands on a specific API endp...

Apr 15, 2024
CVE-2024-1655
8.8

CVE-2024-1655 is an OS command injection vulnerability in certain ASUS WiFi routers that allows authenticated remote attackers to execute arbitrary sy...

Apr 15, 2024
CVE-2024-21756
8.8

This CVE describes an OS command injection vulnerability in Fortinet FortiSandbox that allows attackers to execute arbitrary commands on affected syst...

Apr 9, 2024
CVE-2023-1082
8.8

CVE-2023-1082 is a command injection vulnerability that allows remote attackers with low-privileged access to execute arbitrary commands on affected s...

Apr 9, 2024
CVE-2024-25568
8.8

This CVE describes an OS command injection vulnerability in specific ELECOM wireless LAN routers that allows an unauthenticated attacker on the same n...

Apr 4, 2024
CVE-2024-25002
8.8

This CVE describes a command injection vulnerability in the diagnostics interface of Bosch Network Synchronizer devices. Unauthenticated attackers can...

Mar 25, 2024
CVE-2024-0815
8.8

This vulnerability allows remote command injection in PaddlePaddle's download utility. Attackers can execute arbitrary commands on systems using vulne...

Mar 7, 2024
CVE-2023-39297
8.8

This CVE describes an OS command injection vulnerability in multiple QNAP operating system versions that allows authenticated users to execute arbitra...

Feb 2, 2024
CVE-2023-6078
8.8

This CVE describes an OS command injection vulnerability in BIOVIA Materials Studio products that allows attackers to execute arbitrary commands on af...

Feb 1, 2024
CVE-2023-51217
8.8

This vulnerability allows remote attackers to execute arbitrary code on TenghuTOS TWS-200 devices by sending specially crafted commands to the ping pa...

Jan 18, 2024
CVE-2023-49254
8.8

This vulnerability allows authenticated users to execute arbitrary commands as root by injecting payloads into the 'destination' field of network test...

Jan 12, 2024
CVE-2024-21773
8.8

This vulnerability allows a network-adjacent attacker on the same LAN or Wi-Fi network to execute arbitrary operating system commands on affected TP-L...

Jan 11, 2024
CVE-2024-21833
8.8

This vulnerability allows an attacker on the same local network to execute arbitrary operating system commands on affected TP-LINK devices without aut...

Jan 11, 2024
CVE-2023-29048
8.8

This vulnerability in OX App Suite's OXMF template parser allows attackers to execute arbitrary system commands with the privileges of the non-privile...

Jan 8, 2024
CVE-2023-41288
8.8

This CVE describes an OS command injection vulnerability in QNAP Video Station that allows authenticated users to execute arbitrary commands on the sy...

Jan 5, 2024
CVE-2023-50094
8.8

CVE-2023-50094 is an OS command injection vulnerability in reNgine web application security scanner versions before 2.1.2. An authenticated attacker c...

Jan 1, 2024
CVE-2023-50466
8.8

This CVE describes an authenticated command injection vulnerability in Weintek cMT2078X HMI devices running easyWeb v2.1.3 and OS v20220215. Attackers...

Dec 19, 2023
CVE-2023-48782
8.8

This CVE describes an OS command injection vulnerability in Fortinet FortiWLM that allows attackers to execute arbitrary commands on affected systems....

Dec 13, 2023
CVE-2023-46157
8.8

This vulnerability allows the lowest privilege user in MGT CloudPanel's File-Manager to execute arbitrary operating system commands through file owner...

Dec 8, 2023
CVE-2023-49897
8.8

This CVE describes an OS command injection vulnerability in AE1021PE and AE1021 firmware versions 2.0.9 and earlier. Attackers who can authenticate to...

Dec 6, 2023
CVE-2023-6357
8.8

This vulnerability allows low-privileged remote attackers to execute arbitrary system commands through file system libraries, potentially gaining full...

Dec 5, 2023
CVE-2023-37928
8.8

A post-authentication command injection vulnerability in Zyxel NAS devices allows authenticated attackers to execute arbitrary OS commands by sending ...

Nov 30, 2023
CVE-2023-6201
8.8

This OS command injection vulnerability in Univera Computer System Panorama allows attackers to execute arbitrary commands on the underlying operating...

Nov 28, 2023
CVE-2023-39295
8.8

This CVE describes an OS command injection vulnerability in QuMagie that allows authenticated users to execute arbitrary commands on the system. The v...

Nov 10, 2023
CVE-2023-41345
8.8

This vulnerability in ASUS RT-AX55 routers allows authenticated remote attackers to inject malicious commands through insufficient filtering of specia...

Nov 3, 2023
CVE-2023-41347
8.8

This vulnerability in ASUS RT-AX55 routers allows authenticated remote attackers to inject malicious commands through insufficient filtering of specia...

Nov 3, 2023
CVE-2023-20175
8.8

This vulnerability in Cisco ISE allows authenticated users with at least Read-only privileges to execute arbitrary commands on the underlying operatin...

Nov 1, 2023
CVE-2023-46117
8.8

CVE-2023-46117 is a remote code execution vulnerability in reconFTW caused by inadequate validation of retrieved subdomains. Attackers can exploit thi...

Oct 20, 2023
CVE-2023-23373
8.8

This OS command injection vulnerability in QUSBCam2 allows remote attackers to execute arbitrary commands on affected systems via network requests. Us...

Oct 20, 2023
CVE-2023-43959
8.8

This vulnerability allows remote attackers with administrative access to execute arbitrary code on Yealink SIP-T19P E2 phones via a crafted request to...

Oct 17, 2023
CVE-2023-34985
8.8

This CVE describes an OS command injection vulnerability in Fortinet FortiWLM wireless LAN management systems. Attackers can execute arbitrary command...

Oct 10, 2023
CVE-2023-34987
8.8

This CVE describes an OS command injection vulnerability in Fortinet FortiWLM wireless LAN management systems. Attackers can execute arbitrary command...

Oct 10, 2023
CVE-2023-34989
8.8

This CVE describes an OS command injection vulnerability in Fortinet FortiWLM that allows attackers to execute arbitrary commands on affected systems....

Oct 10, 2023
CVE-2023-36549
8.8

This CVE describes an OS command injection vulnerability in Fortinet FortiWLM wireless LAN management systems. Attackers can execute arbitrary command...

Oct 10, 2023

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,812 CVEs classified as CWE-78, with 717 rated critical and 925 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free