CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,672
Total CVEs
621
Critical
881
High
8.5
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Dell 58
4 Fortinet 57
5 Tp Link 35
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Jvckenwood 26
10 Arubanetworks 24

All OS Command Injection CVEs (1,672)

CVE-2025-43879
9.8

This critical vulnerability allows remote unauthenticated attackers to execute arbitrary operating system commands on affected ELECOM WRH-733GBK and W...

Jun 24, 2025
CVE-2025-6559
9.8

Multiple Sapido wireless router models contain an unauthenticated remote OS command injection vulnerability (CWE-78), allowing attackers to execute ar...

Jun 24, 2025
CVE-2025-34035
9.8

An unauthenticated remote OS command injection vulnerability in EnGenius EnShare Cloud Service allows attackers to execute arbitrary shell commands wi...

Jun 24, 2025
CVE-2025-25038
EPSS 17.6% 9.8

A critical OS command injection vulnerability in MiniDVBLinux allows remote unauthenticated attackers to execute arbitrary commands as root. This affe...

Jun 20, 2025
CVE-2025-44635
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary commands with root privileges on affected H3C routers by bypassing a...

Jun 20, 2025
CVE-2025-50201
EPSS 54.1% 9.8

CVE-2025-50201 is an unauthenticated OS command injection vulnerability in WeGIA web management software that allows attackers to execute arbitrary co...

Jun 19, 2025
CVE-2025-41663
9.8

This critical vulnerability in u-link Management API allows unauthenticated attackers in man-in-the-middle positions to inject arbitrary commands that...

Jun 11, 2025
CVE-2025-44880
9.8

This CVE describes a critical command injection vulnerability in Wavlink WL-WN579A3 routers that allows attackers to execute arbitrary commands on aff...

May 20, 2025
CVE-2025-32002
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary operating system commands on I-O DATA HDL-T Series network attached st...

May 15, 2025
CVE-2025-45858
9.8

This CVE describes a command injection vulnerability in TOTOLINK A3002R routers that allows attackers to execute arbitrary commands on the device. The...

May 13, 2025
CVE-2025-28034
9.8

This CVE describes a pre-authentication remote command execution vulnerability in multiple TOTOLINK router models. Attackers can execute arbitrary com...

Apr 22, 2025
CVE-2025-29042
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-832x routers by injecting malicious code into the macaddr param...

Apr 17, 2025
CVE-2025-29040
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR 823x routers via command injection in the target_addr parameter...

Apr 17, 2025
CVE-2025-28137
EPSS 11.9% 9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on TOTOLINK A810R routers. Attackers can exploit the setNotic...

Apr 15, 2025
CVE-2025-27797
9.8

This CVE describes an OS command injection vulnerability in Wi-Fi AP UNIT 'AC-WPS-11ac series' devices. Remote attackers who can authenticate to the d...

Apr 9, 2025
CVE-2025-3363
9.8

CVE-2025-3363 is a critical OS command injection vulnerability in HGiga's iSherlock web service that allows unauthenticated remote attackers to execut...

Apr 8, 2025
CVE-2025-3361
9.8

CVE-2025-3361 is an unauthenticated OS command injection vulnerability in HGiga iSherlock web service that allows remote attackers to execute arbitrar...

Apr 8, 2025
CVE-2025-26817
9.8

CVE-2025-26817 is an OS command injection vulnerability in Netwrix Password Secure 9.2.0.32454 that allows authenticated attackers to execute arbitrar...

Apr 3, 2025
CVE-2025-25579
EPSS 17.5% 9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3002R routers via command injection in the bandstr parameter of ...

Mar 28, 2025
CVE-2025-28256
9.8

This vulnerability allows remote attackers to execute arbitrary code on TOTOLINK A3100R routers by exploiting improper input sanitization in the setWe...

Mar 28, 2025
CVE-2025-28219
9.8

Netgear DC112A V1.0.0.64 contains an OS command injection vulnerability in the usb_adv.cgi endpoint that allows remote attackers to execute arbitrary ...

Mar 28, 2025
CVE-2025-22398
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands as root on Dell Unity storage syste...

Mar 28, 2025
CVE-2025-28138
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on TOTOLINK A800R routers by exploiting improper input validation in...

Mar 27, 2025
CVE-2025-1316
KEV EPSS 84.9% 9.8

The Edimax IC-7100 network camera has an OS command injection vulnerability (CWE-78) that allows remote code execution. Attackers can send specially c...

Mar 5, 2025
CVE-2024-53584
9.8

OpenPanel v0.3.4 contains an OS command injection vulnerability in the timezone parameter that allows attackers to execute arbitrary commands on the u...

Jan 31, 2025
CVE-2025-0680
9.8

This vulnerability allows remote attackers to execute arbitrary commands on devices connected to the cloud through improper neutralization of special ...

Jan 30, 2025
CVE-2025-20014
9.8

CVE-2025-20014 is a critical OS command injection vulnerability in mySCADA myPRO software that allows unauthenticated attackers to execute arbitrary c...

Jan 29, 2025
CVE-2025-20055
9.8

This CVE describes an OS command injection vulnerability in Y'S corporation STEALTHONE D220/D340 network storage servers. Attackers who can access the...

Jan 14, 2025
CVE-2025-0107
EPSS 88.6% 9.8

An unauthenticated OS command injection vulnerability in Palo Alto Networks Expedition allows attackers to execute arbitrary commands as the www-data ...

Jan 11, 2025
CVE-2024-12847
EPSS 67.1% 9.8

This CVE describes an authentication bypass vulnerability in NETGEAR DGN1000 routers that allows remote unauthenticated attackers to execute arbitrary...

Jan 10, 2025
CVE-2024-9140
9.8

CVE-2024-9140 is a critical OS command injection vulnerability in Moxa cellular routers, secure routers, and network security appliances that allows a...

Jan 3, 2025
CVE-2024-47919
9.8

This vulnerability in Tiki Wiki CMS allows attackers to execute arbitrary operating system commands on the server by injecting malicious input. It aff...

Dec 30, 2024
CVE-2024-52320
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected systems through malicious HTTP requests, leading to remo...

Dec 6, 2024
CVE-2024-48863
9.8

This CVE describes a command injection vulnerability in QNAP License Center that allows remote attackers to execute arbitrary commands on affected sys...

Dec 6, 2024
CVE-2024-49803
9.8

This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Verify Access Appliances. Attackers can achieve...

Nov 29, 2024
CVE-2024-11482
9.8

This critical vulnerability in ESM 11.6.10 allows unauthenticated attackers to access the internal Snowservice API and execute arbitrary commands as r...

Nov 29, 2024
CVE-2024-50374
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary operating system commands with root privileges on affected Advantech w...

Nov 26, 2024
CVE-2024-50372
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary operating system commands with root privileges on affected Advantech w...

Nov 26, 2024
CVE-2024-50370
9.8

This is a critical OS command injection vulnerability in Advantech wireless access points that allows remote unauthenticated attackers to execute arbi...

Nov 26, 2024
CVE-2024-8806
9.8

This critical vulnerability in Cohesive Networks VNS3 allows unauthenticated remote attackers to execute arbitrary commands as root on affected system...

Nov 22, 2024
CVE-2024-52723
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers by exploiting insufficient parameter filtering in ...

Nov 22, 2024
CVE-2024-28892
9.8

An unauthenticated OS command injection vulnerability in GoCast 1.1.3 allows attackers to execute arbitrary commands on affected systems by sending sp...

Nov 21, 2024
CVE-2024-10443
9.8

This CVE describes an OS command injection vulnerability in Synology's photo management applications. Remote attackers can execute arbitrary commands ...

Nov 15, 2024
CVE-2022-1884
9.8

A remote command execution vulnerability in Gogs (Git service) allows attackers to upload malicious files to the .git directory when deployed on Windo...

Nov 15, 2024
CVE-2024-11120
9.8

This CVE describes an OS command injection vulnerability in certain end-of-life GeoVision devices that allows unauthenticated remote attackers to exec...

Nov 15, 2024
CVE-2024-4343
9.8

This CVE describes a critical command injection vulnerability in PrivateGPT's SageMaker integration that allows remote code execution. Attackers can m...

Nov 14, 2024
CVE-2024-36061
9.8

CVE-2024-36061 is a critical OS command injection vulnerability in EnGenius EWS356-FIT wireless access points. Attackers can execute arbitrary command...

Nov 11, 2024
CVE-2020-8007
9.8

CVE-2020-8007 allows remote attackers to execute arbitrary operating system commands on Circontrol Raption EV charging stations through command inject...

Nov 8, 2024
CVE-2024-51252
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfun...

Nov 1, 2024
CVE-2024-10119
9.8

CVE-2024-10119 is a critical OS command injection vulnerability in SECOM WRTM326 wireless routers that allows unauthenticated remote attackers to exec...

Oct 18, 2024

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,672 CVEs classified as CWE-78, with 621 rated critical and 881 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free