Skip to content
Noroxi

CWE-78 · 5,951 records

OS command injection

Why does it happen?

User input is inserted as text into a shell command. The shell may interpret special characters in the input as part of the command.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
const host = req.body.host;exec("ping -c 1 " + host, onResult);

Fixed

ts
const host = req.body.host;if (!/^[a-z0-9.-]{1,253}$/i.test(host)) return res.sendStatus(400);execFile("ping", ["-c", "1", host], onResult);

How to prevent it

  1. 01Instead of running through a shell, use APIs that take arguments as an array.
  2. 02Validate input against an allowlist (for example, hostname format only).
  3. 03Where possible, use a library function instead of an OS command.

CVEs in this class

5,960 records

  • An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    ivanti · standalone sentryJun 9, 2026

  • Cisco HyperFlex HX Command Injection Vulnerabilities

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    cisco · hyperflex hx data platformMay 6, 2021

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dlink · dir-655 firmwareSep 27, 2019

  • login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS comma

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    control-webpanel · webpanelJan 5, 2023

  • DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    draytek · vigor2960 firmwareFeb 1, 2020

  • ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    zyxel · nas326 firmwareMar 4, 2020

  • Argument Injection in PHP-CGI

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpJun 9, 2024

  • D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dlink · dns-320 firmwareFeb 2, 2021

  • A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    exim · eximJun 5, 2019

  • An issue was discovered on Dasan GPON home routers.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dasannetworks · gpon router firmwareMay 3, 2018

  • A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    zyxel · usg flex 100w firmwareMay 12, 2022

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Cisco HyperFlex HX Command Injection Vulnerabilities

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    cisco · hyperflex hx data platformMay 6, 2021

  • The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    synacor · zimbra collaboration suiteOct 2, 2024

  • A command injection vulnerability in the web server of some Hikvision product.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    hikvision · ds-2cd2026g2-iu\/sl firmwareSep 22, 2021

  • Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    realtek · rtl819x jungle software development kitAug 16, 2021

  • An issue was discovered in Webmin <=1.920.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    webmin · webminAug 15, 2019

  • An issue was discovered in SaltStack Salt through 3002.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    saltstack · saltNov 6, 2020

  • Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    zyxel · atp100 firmwareApr 24, 2023

  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    openbsd · opensmtpdJan 29, 2020

  • Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure

    CriticalCVSS 9.9KEVWeaponizedEPSS 99%

    paloaltonetworks · expeditionOct 9, 2024

  • An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    aviatrix · controllerJan 7, 2025

  • SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    contec · sv-cpt-mc310 firmwareMay 12, 2022

  • OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with t

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    dlink · dir-820l firmwareMar 15, 2023

All vulnerability classes