CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,699
Total CVEs
635
Critical
894
High
8.5
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Fortinet 58
4 Dell 58
5 Tp Link 36
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,699)

CVE-2022-33328
9.8

CVE-2022-33328 is a critical command injection vulnerability in Robustel R1510 routers that allows remote attackers to execute arbitrary commands via ...

Jun 30, 2022
CVE-2022-32092
9.8

This CVE describes a command injection vulnerability in D-Link DIR-645 routers where attackers can execute arbitrary commands via the QUERY_STRING par...

Jun 27, 2022
CVE-2022-31767
9.8

CVE-2022-31767 is a critical OS command injection vulnerability in IBM CICS TX that allows remote attackers to execute arbitrary commands on affected ...

Jun 24, 2022
CVE-2022-26147
9.8

CVE-2022-26147 is an OS command injection vulnerability in Quectel RG502Q-EA modems that allows attackers to execute arbitrary commands with root priv...

Jun 21, 2022
CVE-2022-30329
9.8

This CVE describes an OS command injection vulnerability in TRENDnet TEW-831DR routers that allows authenticated attackers to execute arbitrary shell ...

Jun 16, 2022
CVE-2022-31311
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on WAVLINK AERIAL X 1200M routers by sending specia...

Jun 14, 2022
CVE-2022-31446
9.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers by sending specially crafted requests to the Mac parameter ...

Jun 14, 2022
CVE-2022-30308
9.8

CVE-2022-30308 allows unauthenticated attackers to execute arbitrary system commands with root privileges on Festo CECC-X-M1 controllers via command i...

Jun 13, 2022
CVE-2022-30310
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary system commands with root privileges on Festo Controller CECC-X-M1 devices. A...

Jun 13, 2022
CVE-2022-1986
9.8

CVE-2022-1986 is an OS command injection vulnerability in Gogs (a self-hosted Git service) that allows attackers to execute arbitrary commands on the ...

Jun 9, 2022
CVE-2021-42890
9.8

CVE-2021-42890 is a critical remote command injection vulnerability in TOTOLINK EX1200T routers that allows unauthenticated attackers to execute arbit...

Jun 3, 2022
CVE-2021-42884
9.8

CVE-2021-42884 is a remote command injection vulnerability in TOTOLINK EX1200T routers that allows unauthenticated attackers to execute arbitrary comm...

Jun 3, 2022
CVE-2021-42872
9.8

This CVE describes a command injection vulnerability in TOTOLINK EX1200T routers that allows remote attackers to execute arbitrary commands on affecte...

Jun 2, 2022
CVE-2021-34084
9.8

This CVE describes an OS command injection vulnerability in the Turistforeningen node-s3-uploader npm package for Node.js. Attackers can execute arbit...

Jun 2, 2022
CVE-2021-34079
9.8

This CVE describes an OS command injection vulnerability in Mintzo Docker-Tester that allows attackers to execute arbitrary commands on the host syste...

Jun 2, 2022
CVE-2021-34082
9.8

This vulnerability allows attackers to execute arbitrary operating system commands on systems running the vulnerable proctree Node.js package. Attacke...

Jun 2, 2022
CVE-2022-1813
9.8

This CVE-2022-1813 is an OS command injection vulnerability in the rengine reconnaissance tool that allows attackers to execute arbitrary commands on ...

May 22, 2022
CVE-2022-30105
9.8

Belkin N300 routers running firmware version 1.00.08 contain multiple remote command injection vulnerabilities in the /setting_hidden.asp script. Atta...

May 18, 2022
CVE-2022-29516
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on affected FUJITSU Network IPCOM devices through the web co...

May 18, 2022
CVE-2022-1357
9.8

CVE-2022-1357 is a critical OS command injection vulnerability in Cambium Networks cnMaestro On-Premise that allows unauthenticated attackers to execu...

May 17, 2022
CVE-2021-42897
9.8

This vulnerability allows remote attackers to execute arbitrary commands on FeMiner wms V1.0 systems by exploiting improper input validation in the da...

May 16, 2022
CVE-2022-28910
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink N600R routers by injecting malicious commands into the devicename...

May 10, 2022
CVE-2022-28912
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink N600R routers via command injection in the firmware upgrade filen...

May 10, 2022
CVE-2022-28915
9.8

This CVE describes a command injection vulnerability in D-Link DIR-816 routers that allows attackers to execute arbitrary commands on the device. Atta...

May 10, 2022
CVE-2022-28895
9.8

This CVE describes a command injection vulnerability in D-Link DIR882 routers that allows attackers to execute arbitrary commands with root privileges...

May 10, 2022
CVE-2022-28901
9.8

This CVE describes a command injection vulnerability in D-Link DIR882 routers that allows attackers to execute arbitrary commands with root privileges...

May 10, 2022
CVE-2022-28906
9.8

This CVE describes a command injection vulnerability in TOTOLink N600R routers where an attacker can execute arbitrary commands via the langtype param...

May 10, 2022
CVE-2022-28908
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLink N600R routers via command injection in the ipdoamin parameter. At...

May 10, 2022
CVE-2022-28581
9.8

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers that allows attackers to execute arbitrary commands on the device. At...

May 5, 2022
CVE-2022-28583
9.8

This CVE describes a command injection vulnerability in TOTOlink A7100RU routers that allows attackers to execute arbitrary commands on the device. At...

May 5, 2022
CVE-2021-41739
9.8

This CVE describes an OS command injection vulnerability in Artica Proxy's cyrus.events.php file. Attackers can execute arbitrary operating system com...

May 5, 2022
CVE-2022-28557
9.8

This CVE describes a command injection vulnerability in Tenda AC15 routers that allows attackers to execute arbitrary commands on the device. When com...

May 4, 2022
CVE-2022-28055
9.8

CVE-2022-28055 is a command injection vulnerability in FusionPBX's email log download function that allows authenticated attackers to execute arbitrar...

May 4, 2022
CVE-2022-28573
9.8

CVE-2022-28573 is a critical command injection vulnerability in D-Link DIR-823-Pro routers that allows attackers to execute arbitrary system commands ...

May 2, 2022
CVE-2022-28571
9.8

D-Link DIR-882 routers running firmware version A1_FW130B06 contain a command injection vulnerability in the /usr/bin/cli binary. This allows authenti...

May 2, 2022
CVE-2021-46422
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on Telesquare SDT-CW3B1 devices without authentication. Atta...

Apr 27, 2022
CVE-2022-1440
9.8

CVE-2022-1440 is a command injection vulnerability in git-interface@2.1.1 that allows attackers to execute arbitrary operating system commands by expl...

Apr 22, 2022
CVE-2022-29080
9.8

The npm-dependency-versions package through version 0.3.0 contains a command injection vulnerability that allows attackers to execute arbitrary shell ...

Apr 12, 2022
CVE-2022-27268
9.8

CVE-2022-27268 is a remote code execution vulnerability in InHand Networks InRouter 900 Industrial 4G Router that allows attackers to execute arbitrar...

Apr 10, 2022
CVE-2022-27270
9.8

CVE-2022-27270 is a remote code execution vulnerability in InHand Networks InRouter 900 Industrial 4G Routers that allows attackers to execute arbitra...

Apr 10, 2022
CVE-2022-27272
9.8

CVE-2022-27272 is a remote code execution vulnerability in InHand Networks InRouter 900 Industrial 4G Router that allows attackers to execute arbitrar...

Apr 10, 2022
CVE-2022-27274
9.8

CVE-2022-27274 is a critical remote code execution vulnerability in InHand Networks InRouter 900 Industrial 4G Routers. Attackers can execute arbitrar...

Apr 10, 2022
CVE-2022-27276
9.8

CVE-2022-27276 is a remote code execution vulnerability in InHand Networks InRouter 900 Industrial 4G Router that allows attackers to execute arbitrar...

Apr 10, 2022
CVE-2022-23900
9.8

This CVE describes a command injection vulnerability in the Wavlink WL-WN531P3 router's API that allows remote attackers to execute arbitrary commands...

Apr 7, 2022
CVE-2021-46007
9.8

CVE-2021-46007 is a critical command injection vulnerability in TOTOLINK A3100R routers that allows attackers to execute arbitrary operating system co...

Mar 30, 2022
CVE-2022-26258
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on D-Link DIR-820L routers via HTTP POST requests to the 'get...

Mar 28, 2022
CVE-2022-27811
9.8

CVE-2022-27811 is a critical OS command injection vulnerability in GNOME OCRFeeder that allows attackers to execute arbitrary commands on the system b...

Mar 24, 2022
CVE-2022-26290
9.8

CVE-2022-26290 is a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. This affect...

Mar 24, 2022
CVE-2022-26265
9.8

CVE-2022-26265 is a critical remote command execution vulnerability in Contao Managed Edition v1.5.0 that allows attackers to execute arbitrary comman...

Mar 18, 2022
CVE-2022-25438
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC9 routers via the SetIPTVCfg function. Attackers can gain full con...

Mar 18, 2022

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,699 CVEs classified as CWE-78, with 635 rated critical and 894 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free