CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,687
Total CVEs
629
Critical
888
High
8.5
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Dell 58
4 Fortinet 57
5 Tp Link 35
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,687)

CVE-2024-24330
9.8

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. Att...

Jan 30, 2024
CVE-2024-24332
9.8

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers, allowing attackers to execute arbitrary commands via the url paramete...

Jan 30, 2024
CVE-2023-38319
9.8

CVE-2023-38319 is a command injection vulnerability in OpenNDS that allows attackers with access to the configuration file to execute arbitrary operat...

Jan 26, 2024
CVE-2023-38317
9.8

CVE-2023-38317 is a command injection vulnerability in OpenNDS that allows attackers with access to the configuration file to execute arbitrary operat...

Jan 26, 2024
CVE-2023-52026
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOlink EX1800T routers by exploiting improper input validation in the se...

Jan 12, 2024
CVE-2024-23060
9.8

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers via the ip parameter in the setDmzCfg function. Attackers can execute ...

Jan 11, 2024
CVE-2024-22942
9.8

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. Att...

Jan 11, 2024
CVE-2024-23058
9.8

This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands via the pass param...

Jan 11, 2024
CVE-2023-51984
9.8

CVE-2023-51984 is a critical command injection vulnerability in D-Link DIR-822+ routers that allows remote attackers to execute arbitrary commands wit...

Jan 11, 2024
CVE-2023-52029
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOlink A3700R routers via the setDiagnosisCfg function. Attackers can ga...

Jan 11, 2024
CVE-2023-51123
9.8

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-815 routers by sending a specially crafted POST request to the soap...

Jan 10, 2024
CVE-2023-51094
9.8

Tenda M3 routers running firmware version 1.0.0.12(4856) contain a command injection vulnerability in the TendaTelnet function. This allows remote att...

Dec 26, 2023
CVE-2023-51098
9.8

This CVE describes a command injection vulnerability in Tenda W9 routers that allows attackers to execute arbitrary commands on the device. Attackers ...

Dec 26, 2023
CVE-2023-51100
9.8

This CVE describes a command injection vulnerability in Tenda W9 routers that allows attackers to execute arbitrary commands on the device. The vulner...

Dec 26, 2023
CVE-2021-42796
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on AVEVA Edge systems. It affects all versions R2020 and prior, pote...

Dec 16, 2023
CVE-2023-42495
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on Dasan Networks W-Web devices through improper input sanit...

Dec 13, 2023
CVE-2023-46454
9.8

This vulnerability allows remote attackers to execute arbitrary shell commands on GL.iNET GL-AR300M routers by injecting malicious commands into packa...

Dec 12, 2023
CVE-2023-47254
9.8

This vulnerability allows remote attackers to execute arbitrary system commands on DrayTek Vigor167 routers via OS command injection in the CLI interf...

Dec 9, 2023
CVE-2023-48808
9.8

This CVE describes a command injection vulnerability in TOTOLINK X6000R routers where improper input validation in the shttpd component allows attacke...

Nov 30, 2023
CVE-2023-48811
9.8

This CVE describes a command injection vulnerability in TOTOLINK X6000R routers where improper input validation in the shttpd component allows attacke...

Nov 30, 2023
CVE-2023-48802
9.8

This CVE describes a command injection vulnerability in TOTOLINK X6000R routers where improper input validation in the shttpd component allows attacke...

Nov 30, 2023
CVE-2023-48804
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers by exploiting improper input validation in the sht...

Nov 30, 2023
CVE-2023-48806
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X6000R routers by exploiting improper input validation in the sht...

Nov 30, 2023
CVE-2023-4473
9.8

An unauthenticated command injection vulnerability in Zyxel NAS web servers allows attackers to execute arbitrary OS commands by sending specially cra...

Nov 30, 2023
CVE-2023-35138
9.8

This critical command injection vulnerability in Zyxel NAS devices allows unauthenticated attackers to execute arbitrary operating system commands via...

Nov 30, 2023
CVE-2023-3741
9.8

This critical OS command injection vulnerability in NEC DT900/DT900S Series allows attackers to execute arbitrary commands on affected devices. All ve...

Nov 30, 2023
CVE-2023-3368
9.8

CVE-2023-3368 is an unauthenticated command injection vulnerability in Chamilo LMS that allows remote attackers to execute arbitrary commands on affec...

Nov 28, 2023
CVE-2023-4149
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary system commands with root privileges through the web-based ma...

Nov 21, 2023
CVE-2023-6019
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on systems running vulnerable versions of Ra...

Nov 16, 2023
CVE-2023-36553
9.8

This CVE describes an OS command injection vulnerability in Fortinet FortiSIEM that allows attackers to execute arbitrary commands on affected systems...

Nov 14, 2023
CVE-2023-47104
9.8

This vulnerability in tinyfiledialogs allows shell command injection through insufficient input sanitization of shell metacharacters in dialog titles ...

Oct 30, 2023
CVE-2023-45467
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Netis N3Mv2 routers by injecting malicious input into the ntpServIP parame...

Oct 13, 2023
CVE-2023-36550
9.8

This CVE describes an OS command injection vulnerability in Fortinet FortiWLM that allows attackers to execute arbitrary commands on affected systems ...

Oct 10, 2023
CVE-2023-36547
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on Fortinet FortiWLM devices through crafted HTTP GET reques...

Oct 10, 2023
CVE-2023-30805
9.8

Sangfor Next-Gen Application Firewall NGAF8.0.17 has an unauthenticated remote command injection vulnerability in the /LogInOut.php endpoint. Attacker...

Oct 10, 2023
CVE-2023-33269
9.8

CVE-2023-33269 is a critical OS command injection vulnerability in DTS Monitoring 3.57.0 that allows attackers to execute arbitrary commands on the un...

Oct 3, 2023
CVE-2023-33271
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on DTS Monitoring servers through command injection in the S...

Oct 3, 2023
CVE-2023-33273
9.8

CVE-2023-33273 is a critical OS command injection vulnerability in DTS Monitoring 3.57.0 that allows attackers to execute arbitrary commands on the se...

Oct 3, 2023
CVE-2023-43893
9.8

This CVE describes a command injection vulnerability in Netis N3Mv2 routers version V1.0.1.865. Attackers can execute arbitrary commands on the device...

Oct 2, 2023
CVE-2023-44080
9.8

This vulnerability allows remote attackers to execute arbitrary code on PGYER CodeFever systems by sending a specially crafted request to the branchLi...

Sep 27, 2023
CVE-2023-3767
9.8

An OS command injection vulnerability in EasyPHP Webserver 14.1 allows attackers to execute arbitrary commands on the underlying operating system by s...

Sep 27, 2023
CVE-2023-28614
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on Freewill iFIS (SMART Trade) servers by injecting shell me...

Sep 15, 2023
CVE-2023-41149
9.8

CVE-2023-41149 is an OS command injection vulnerability in F-RevoCRM versions 7.3.7 and 7.3.8 that allows authenticated attackers to execute arbitrary...

Sep 6, 2023
CVE-2023-40582
9.8

CVE-2023-40582 is a command injection vulnerability in find-exec utility versions before 1.0.3 that allows attackers to execute arbitrary shell comman...

Aug 30, 2023
CVE-2023-40837
9.8

This vulnerability allows remote command execution on Tenda AC6 routers by exploiting unfiltered input in the formSetIptv function. Attackers can exec...

Aug 30, 2023
CVE-2023-40839
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC6 routers by sending specially crafted requests to the 'formSetIpt...

Aug 30, 2023
CVE-2023-41109
9.8

CVE-2023-41109 is an unauthenticated OS command injection vulnerability in SmartNode SN200 devices. Attackers can execute arbitrary commands on affect...

Aug 28, 2023
CVE-2023-40069
9.8

This CVE describes an OS command injection vulnerability in specific ELECOM wireless LAN routers, allowing attackers with access to the device to exec...

Aug 18, 2023
CVE-2023-38692
9.8

CVE-2023-38692 is a critical command injection vulnerability in CloudExplorer Lite's module management installation function that allows attackers to ...

Aug 4, 2023
CVE-2023-33374
9.8

CVE-2023-33374 allows remote attackers to execute arbitrary operating system commands on Connected IO devices by abusing a management protocol feature...

Aug 4, 2023

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,687 CVEs classified as CWE-78, with 629 rated critical and 888 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free