CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface th
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function t
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol functi
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that al
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that al
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function u
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function u
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function t
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function tha
An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute a
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networ
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutr
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-esc
An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login funct
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2
Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remo
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability i
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi inter
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication u
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to s
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inje
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate
Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI
PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are
An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated at
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c
UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s devi
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workfl
bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involvi
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started