CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A remote attacker with high privileges may use a deleting file function to inject OS commands.
AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented,
A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC t
A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authe
A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an aut
A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due
Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sen
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter
The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with admi
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, US
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, US
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and
An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allo
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is s
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil
Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of t
Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitatio
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not su
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authen
The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator inter
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to
An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies
Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies
Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies
Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started