CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,699
Total CVEs
635
Critical
894
High
8.5
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Fortinet 58
4 Dell 58
5 Tp Link 36
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,699)

CVE-2021-45966
9.8

This vulnerability allows remote attackers to execute arbitrary code on Pascom Cloud Phone System servers by sending shell metacharacters to the /serv...

Mar 18, 2022
CVE-2022-22273
9.8

This CVE allows attackers to execute arbitrary operating system commands on vulnerable SonicWall Secure Remote Access (SRA) and Secure Mobile Access (...

Mar 17, 2022
CVE-2022-27003
9.8

This CVE describes a critical command injection vulnerability in Totolink routers that allows attackers to execute arbitrary system commands via the T...

Mar 15, 2022
CVE-2022-27005
9.8

This CVE describes a critical command injection vulnerability in Totolink routers that allows attackers to execute arbitrary commands via the hostName...

Mar 15, 2022
CVE-2022-26206
9.8

This CVE describes a critical command injection vulnerability in multiple Totolink router models. Attackers can execute arbitrary system commands by s...

Mar 15, 2022
CVE-2022-26208
9.8

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the we...

Mar 15, 2022
CVE-2022-26210
9.8

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the Fi...

Mar 15, 2022
CVE-2022-26212
9.8

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the se...

Mar 15, 2022
CVE-2022-26214
9.8

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the ho...

Mar 15, 2022
CVE-2022-26991
9.8

This CVE describes a command injection vulnerability in Arris routers that allows attackers to execute arbitrary commands by manipulating the TimeZone...

Mar 15, 2022
CVE-2022-26993
9.8

This CVE describes a command injection vulnerability in Arris routers that allows attackers to execute arbitrary system commands by manipulating PPPoE...

Mar 15, 2022
CVE-2022-25621
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on affected NEC UNIVERGE wireless access points. Attackers c...

Mar 11, 2022
CVE-2022-24193
9.8

CVE-2022-24193 is a command injection vulnerability in CasaOS versions before 0.2.7 that allows attackers to execute arbitrary commands on the system....

Mar 10, 2022
CVE-2022-0848
9.8

CVE-2022-0848 is a critical OS command injection vulnerability in part-db software that allows remote attackers to execute arbitrary commands on the s...

Mar 4, 2022
CVE-2022-0841
9.8

This CVE describes an OS command injection vulnerability in the npm-lockfile package versions 2.0.3 and 2.0.4. Attackers can execute arbitrary command...

Mar 3, 2022
CVE-2021-4039
9.8

This CVE-2021-4039 is a command injection vulnerability in Zyxel NWA-1100-NH access point web interface that allows authenticated attackers to execute...

Mar 1, 2022
CVE-2020-12775
9.8

CVE-2020-12775 is a command injection vulnerability in the Hicos citizen certificate client-side component that allows unauthenticated remote attacker...

Mar 1, 2022
CVE-2022-25061
9.8

This CVE describes a command injection vulnerability in TP-LINK TL-WR840N routers that allows attackers to execute arbitrary commands on the device. T...

Feb 25, 2022
CVE-2022-25064
9.8

This vulnerability allows remote attackers to execute arbitrary code on TP-LINK TL-WR840N routers via a crafted IPv6 address payload in the oal_wan6_s...

Feb 25, 2022
CVE-2022-25076
9.8

This CVE describes a command injection vulnerability in TOTOLink A800R routers that allows attackers to execute arbitrary commands via the QUERY_STRIN...

Feb 24, 2022
CVE-2022-25078
9.8

This CVE describes a command injection vulnerability in TOTOLink A3600R routers that allows attackers to execute arbitrary commands via the QUERY_STRI...

Feb 24, 2022
CVE-2022-25080
9.8

This critical vulnerability in TOTOLink A830R routers allows remote attackers to execute arbitrary commands via the QUERY_STRING parameter in the Main...

Feb 24, 2022
CVE-2022-25082
9.8

This CVE describes a command injection vulnerability in TOTOLink A950RG routers that allows attackers to execute arbitrary system commands via the QUE...

Feb 24, 2022
CVE-2022-25084
9.8

This critical vulnerability in TOTOLink T6 routers allows remote attackers to execute arbitrary operating system commands via the QUERY_STRING paramet...

Feb 24, 2022
CVE-2021-46315
9.8

This CVE describes a remote command execution vulnerability in D-Link DIR-846 routers where attackers can inject shell commands through SSID parameter...

Feb 17, 2022
CVE-2021-45382
9.8

A critical Remote Command Execution vulnerability exists in multiple D-Link router models via the DDNS function in the ncc2 binary. Attackers can exec...

Feb 17, 2022
CVE-2022-23389
9.8

PublicCMS v4.0 contains a remote code execution vulnerability via the cmdarray parameter that allows attackers to execute arbitrary commands on the se...

Feb 14, 2022
CVE-2022-24552
9.8

This vulnerability allows authenticated non-root users to execute arbitrary commands with root privileges through the StarWind REST API. Attackers can...

Feb 6, 2022
CVE-2021-29393
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary system commands on NorthStar Club Management servers by injecting mali...

Feb 4, 2022
CVE-2021-45987
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda G1 and G3 routers by injecting malicious input into the hostName par...

Feb 4, 2022
CVE-2021-40408
9.8

This CVE describes an OS command injection vulnerability in Reolink RLC-410W cameras where the DDNS username parameter is not properly validated. Atta...

Jan 28, 2022
CVE-2021-33962
9.8

This CVE describes an OS command injection vulnerability in China Mobile An Lianbao WF-1 routers that allows attackers to execute arbitrary commands o...

Jan 14, 2022
CVE-2021-43857
9.8

CVE-2021-43857 is a critical remote code execution vulnerability in Gerapy, a distributed crawler management framework. Attackers can execute arbitrar...

Dec 27, 2021
CVE-2021-39065
9.8

This vulnerability allows remote attackers to execute arbitrary commands on IBM Spectrum Copy Data Management systems due to improper input validation...

Dec 13, 2021
CVE-2021-44685
9.8

CVE-2021-44685 is a critical OS command injection vulnerability in Git-it that allows attackers to execute arbitrary commands on the system. Users run...

Dec 7, 2021
CVE-2021-43033
9.8

CVE-2021-43033 is a critical remote code execution vulnerability in Kaseya Unitrends Backup Appliance's bpserverd daemon that allows attackers to exec...

Dec 6, 2021
CVE-2021-38685
9.8

This is a critical command injection vulnerability in QNAP VioStor devices that allows remote attackers to execute arbitrary commands on affected syst...

Nov 26, 2021
CVE-2021-20850
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on PowerCMS servers through the XMLRPC API. It affects Power...

Nov 24, 2021
CVE-2021-41280
9.8

CVE-2021-41280 is a critical command injection vulnerability in Sharetribe Go marketplace software that allows attackers to execute arbitrary operatin...

Nov 19, 2021
CVE-2020-25367
9.8

This CVE describes a command injection vulnerability in the HNAP1 protocol of D-Link DIR-823G routers. Attackers can execute arbitrary commands via sh...

Nov 4, 2021
CVE-2020-36378
9.8

CVE-2020-36378 is a command injection vulnerability in aaptjs packageCmd function that allows attackers to execute arbitrary code by controlling fileP...

Oct 31, 2021
CVE-2020-36380
9.8

CVE-2020-36380 is a critical OS command injection vulnerability in aaptjs 1.3.1 that allows attackers to execute arbitrary code by manipulating filePa...

Oct 31, 2021
CVE-2020-36376
9.8

This vulnerability in aaptjs 1.3.1 allows attackers to execute arbitrary code via the filePath parameter in the list function. It affects systems usin...

Oct 31, 2021
CVE-2011-2195
9.8

CVE-2011-2195 is a critical remote code execution vulnerability in WebSVN 2.3.2 that allows unauthenticated attackers to execute arbitrary commands on...

Oct 26, 2021
CVE-2021-20837
9.8

CVE-2021-20837 is a critical remote command injection vulnerability in Movable Type's XMLRPC API that allows unauthenticated attackers to execute arbi...

Oct 26, 2021
CVE-2021-27561
9.8

CVE-2021-27561 is an unauthenticated command injection vulnerability in Yealink Device Management that allows remote attackers to execute arbitrary co...

Oct 15, 2021
CVE-2021-42071
9.8

CVE-2021-42071 is a critical remote command execution vulnerability in Visual Tools DVR VX16 software where an unauthenticated attacker can execute ar...

Oct 7, 2021
CVE-2021-37925
9.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Zoho ManageEngine ADManager Plus servers. Attacker...

Sep 22, 2021
CVE-2021-36260
9.8

CVE-2021-36260 is a critical command injection vulnerability in Hikvision web servers that allows unauthenticated attackers to execute arbitrary comma...

Sep 22, 2021
CVE-2021-37913
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary system commands on HGiga OAKlouds mobile portal servers by injecting m...

Sep 15, 2021

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,699 CVEs classified as CWE-78, with 635 rated critical and 894 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free