CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmw
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow a
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Comp
The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0
A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF
Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges cou
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system l
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version
File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by c
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows att
In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via
Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to op
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c
All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or
All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check'
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticat
The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 execu
pymedusa is an automatic video library manager for TV Shows. In versions prior 1.0.12 an attacker with access to the web
discordrb is an implementation of the Discord API using Ruby. In discordrb before commit `91e13043ffa` the `encoder.rb`
yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of Y
Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(),
NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `
OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutral
An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2
OS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a networ
Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allo
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R670
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-W
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injectio
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to ex
A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 throu
A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected pro
Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to
Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjac
Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to
Deco M4 firmware versions prior to 'Deco M4(JP)_V2_1.5.8 Build 20230619' allows a network-adjacent authenticated attacke
Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected pro
Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authentic
A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the forem
OS command injection vulnerability in WRC-X3000GS2-W v1.05 and earlier, WRC-X3000GS2-B v1.05 and earlier, and WRC-X3000G
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started