CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on t
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenti
The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may all
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS comma
IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary com
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it int
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitr
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for di
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to e
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute a
A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execut
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devi
The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulner
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command inj
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she
Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.
ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unaut
D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attack
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO
In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" para
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate
USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because som
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function
MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing c
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Com
An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4
An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302
An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4
An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302
An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V
Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started