CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into
Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level command
Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level c
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web inter
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web inter
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web inter
mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scan
OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via
Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr a
An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell co
Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote
ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticate
The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not ne
Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command inj
HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHC
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DM
An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificat
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authen
Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command exec
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in th
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in th
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in th
OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the Act
An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev ma
An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authentic
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in
NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0
FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.
OS command injection vulnerability in GUI setting page of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allow
OS command injection vulnerability in the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 al
Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/a
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execut
Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This all
Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthent
An OS command injection vulnerability exists in the web interface /action/iperf functionality of Abode Systems, Inc. iot
An OS command injection vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems
Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for
GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the
In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started