CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,852)
CVE-2021-23412 is a command injection vulnerability in the gitlogplus npm package that allows attackers to execute arbitrary commands on the host syst...
Jul 23, 2021CVE-2021-0265 is an unauthenticated remote code execution vulnerability in Juniper Networks AppFormix Agent's REST API. Attackers can execute arbitrar...
Apr 22, 2021This vulnerability allows remote attackers to execute arbitrary commands on affected Aruba Instant Access Point devices without authentication. It aff...
Mar 30, 2021CVE-2020-35851 is a command injection vulnerability in HGiga MailSherlock email security appliances. Attackers can exploit improper parameter validati...
Dec 31, 2020This vulnerability in the systeminformation npm package allows attackers to execute arbitrary commands on affected systems through prototype pollution...
Nov 27, 2020An OS command injection vulnerability in TP-Link Archer BE230 routers allows adjacent authenticated attackers to execute arbitrary commands. This coul...
Feb 2, 2026An OS command injection vulnerability in TP-Link Archer BE230 routers allows adjacent authenticated attackers to execute arbitrary commands. This coul...
Feb 2, 2026An authenticated OS command injection vulnerability in TP-Link Archer BE230 routers allows attackers on the same network to execute arbitrary commands...
Feb 2, 2026An authenticated OS command injection vulnerability in TP-Link Archer BE230 routers allows attackers on the same network to execute arbitrary commands...
Feb 2, 2026An OS command injection vulnerability in TP-Link Archer BE230 routers allows adjacent authenticated attackers to execute arbitrary commands. Successfu...
Feb 2, 2026CVE-2025-9974 is an OS command injection vulnerability in the unified WEBUI application of Nokia ONT/Beacon devices. Authenticated attackers with low ...
Feb 2, 2026CVE-2026-24129 is a command injection vulnerability in Runtipi that allows authenticated users to execute arbitrary system commands on the host server...
Jan 22, 2026This CVE describes a command injection vulnerability in TP-Link WA850RE range extenders' httpd modules. Authenticated attackers on the same network ca...
Dec 18, 2025This vulnerability allows authenticated attackers to execute arbitrary operating system commands with root privileges on TRENDnet TEW-657BRM routers. ...
Nov 26, 2025This vulnerability in Red Hat Satellite's Foreman component allows authenticated users with edit_settings permissions to execute arbitrary commands on...
Nov 5, 2025This CVE describes an OS command injection vulnerability in LemonLDAP::NG's Safe jail feature. Administrators with rule editing privileges can execute...
Sep 17, 2025This command injection vulnerability in Tautulli allows attackers with administrative access to execute arbitrary commands on the server, potentially ...
Sep 9, 2025This CVE describes an OS command injection vulnerability in Deco BE65 Pro mesh Wi-Fi systems that allows authenticated users to execute arbitrary comm...
Apr 11, 2025This CVE describes an OS command injection vulnerability in D-Link DSL-3782 routers via the samba_wg and samba_nbn parameters. Attackers can execute a...
Feb 18, 2025This CVE describes an OS command injection vulnerability in D-Link DSL-3782 routers via the public_type parameter. Attackers can execute arbitrary ope...
Feb 18, 2025This CVE describes an OS command injection vulnerability in D-Link DSL-3782 routers that allows attackers to execute arbitrary operating system comman...
Feb 18, 2025This vulnerability allows remote attackers to execute arbitrary code on TP-Link TL-WPA8630 powerline adapters via command injection in the 'devpwd' pa...
Feb 7, 2025An authenticated remote code execution vulnerability in TP-Link Archer routers allows attackers with network access to execute arbitrary commands on a...
Dec 2, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on EnGenius EWS356-FIR wireless access points via the Contro...
Nov 27, 2024This CVE describes an OS command injection vulnerability in AIPHONE IX SYSTEM and IXG SYSTEM intercom systems. An authenticated attacker on the same n...
Nov 22, 2024This CVE describes a command injection vulnerability in Trend Micro Deep Security 20 Agent's manual scan feature. Attackers with local access or domai...
Nov 19, 2024This CVE describes an OS command injection vulnerability in the RP562B Mesh Wi-Fi router firmware. Network-adjacent authenticated attackers can execut...
Nov 12, 2024This CVE describes a command injection vulnerability in Netgear XR300 routers that allows attackers to execute arbitrary operating system commands by ...
Nov 5, 2024This CVE describes a command injection vulnerability in Netgear R8500 routers that allows attackers to execute arbitrary operating system commands by ...
Nov 5, 2024This CVE describes a command injection vulnerability in specific Netgear router models that allows attackers to execute arbitrary operating system com...
Nov 5, 2024This vulnerability allows attackers to execute arbitrary operating system commands on Netgear R8500 routers by sending specially crafted requests to t...
Nov 5, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on Netgear XR300 routers by sending specially crafted reques...
Nov 5, 2024This CVE describes a command injection vulnerability in specific Netgear router models that allows attackers to execute arbitrary operating system com...
Nov 5, 2024This vulnerability allows attackers to execute arbitrary operating system commands on Netgear R8500 routers by sending specially crafted requests to t...
Nov 5, 2024DrayTek Vigor3900 routers running firmware version 1.5.1.3 contain a post-authentication command injection vulnerability in the OpenVPN configuration ...
Nov 4, 2024DrayTek Vigor3900 routers version 1.5.1.3 contain a post-authentication command injection vulnerability in the mainfunction.cgi endpoint. Attackers wi...
Nov 4, 2024DrayTek Vigor3900 firmware version 1.5.1.3 contains a post-authentication command injection vulnerability in the delete_wlan_profile function. An atta...
Nov 4, 2024DrayTek Vigor3900 firmware version 1.5.1.3 contains a post-authentication command injection vulnerability in the mainfunction.cgi endpoint. An attacke...
Nov 4, 2024This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfun...
Nov 4, 2024This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfun...
Nov 4, 2024This vulnerability allows authenticated attackers to execute arbitrary commands on DrayTek Vigor2960 routers by injecting malicious commands into the ...
Oct 28, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on affected D-Link routers via command injection in the MacA...
Oct 17, 2024This CVE describes multiple command injection vulnerabilities in D-Link DIR-882 and DIR-878 routers that allow attackers to execute arbitrary operatin...
Oct 17, 2024This CVE describes a command injection vulnerability in D-Link DIR-882 and DIR-878 routers that allows attackers to execute arbitrary operating system...
Oct 17, 2024This CVE describes a command injection vulnerability in D-Link DIR-882 and DIR-878 routers that allows attackers to execute arbitrary operating system...
Oct 17, 2024This CVE describes a command injection vulnerability in specific D-Link router models that allows attackers to execute arbitrary operating system comm...
Oct 17, 2024This vulnerability allows remote attackers to execute arbitrary code on TP-LINK TL-WDR5620 v2.3 routers via the httpProcDataSrv function. Attackers ca...
Oct 4, 2024Syrotech SY-GOPON-8OLT-L3 version 1.6.0_240629 contains an authenticated command injection vulnerability (CWE-78) that allows attackers with valid cre...
Oct 3, 2024This CVE describes a command injection vulnerability in Magnet Forensics AXIOM's Android device image acquisition functionality. Network-adjacent atta...
Aug 21, 2024This CVE describes a command injection vulnerability in Comtrend routers that allows authenticated users to execute arbitrary commands on the device b...
Jun 10, 2024About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,852 CVEs classified as CWE-78, with 740 rated critical and 942 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free