CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute
The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arb
The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute a
The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot command
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, rem
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, rem
The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the funct
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys paramete
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root R
The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote a
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect e
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability all
A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability all
QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated atta
QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attac
OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arb
OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands w
The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject an
QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inj
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 R
An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.9736
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.
In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter va
In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since t
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shel
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of s
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dns
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to pat
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS comma
Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access cont
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.
The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network inte
The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interfa
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 an
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI,
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Ap
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started