OS Command Injection (CWE-78)
In CWE-78 the product assembles an operating system command from outside input and does not neutralize elements that change the command before it runs. MITRE describes two forms: one where input becomes arguments to a fixed program, and one where input selects the program and its commands outright. Web applications that call the OS are a typical setting.
About CWE-78
Unauthorized OS commands can disable the product or read and modify data the attacker could not reach directly. Because the application runs the commands, the activity appears to come from the application or its owner.
Mitigations
- +Replace calls to external processes with library functions that provide the same behavior.
- +Use structured mechanisms that keep data separate from the command, such as APIs that take arguments as a list.
- +Keep data used to build commands out of external control, for example by holding it in server-side session state.
- +Quote arguments and escape special characters when dynamic commands cannot be avoided, using a strict allowlist.
- +Run the code in a sandbox such as a chroot jail, AppArmor or SELinux to limit which commands and files are reachable.
Detection
Automated static analysis can often find this weakness through data flow analysis, and dynamic testing with fuzzing has moderate effectiveness according to MITRE.
CWE-78 Vulnerabilities
111 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | SonicWall | 7.8 | 10.8% | KEV | 2026-09-01 |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` | kestra-io | 10.0 | 2.1% | KEV | 2026-06-26 |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | Zimbra | 8.9 | 71.7% | KEV | 2026-08-13 |
| CVE-2026-16812 | VeloCloud Orchestrator OS Command Injection | Arista Networks | 10.0 | 1.0% | KEV | 2026-07-27 |
| CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability | Fortinet | 9.1 | 76.1% | KEV | 2026-06-09 |
| CVE-2026-39808 | Fortinet FortiSandbox OS Command Injection Vulnerability | Fortinet | 9.1 | 47.4% | KEV | 2026-04-14 |
| CVE-2025-67038 | Lantronix EDS5000, G520, and X300 OS Command Injection | Lantronix | 9.8 | 20.0% | KEV | 2026-03-11 |
| CVE-2026-10520 | Ivanti Sentry OS Command Injection Vulnerability | ivanti | 10.0 | 99.9% | KEV | 2026-06-09 |
| CVE-2026-42271 | LiteLLM: Authenticated command execution via MCP stdio test endpoints | BerriAI | 8.7 | 92.6% | KEV | 2026-05-08 |
| CVE-2026-25108 | Soliton Systems K.K FileZen OS Command Injection Vulnerability | Soliton Systems K.K. | 8.8 | 5.2% | KEV | 2026-02-13 |
| CVE-2026-1731 | Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) | BeyondTrust | 9.9 | 90.9% | KEV | 2026-02-06 |
| CVE-2025-11953 | Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests | - | 9.8 | 94.0% | KEV | 2025-11-03 |
| CVE-2025-64328 | FreePBX Administration GUI is Vulnerable to Authenticated Command Injection | FreePBX | 8.6 | 84.6% | KEV | 2025-11-07 |
| CVE-2025-66644 | Array Networks ArrayOS AG OS Command Injection Vulnerability | Array Networks | 7.2 | 3.4% | KEV | 2025-12-05 |
| CVE-2025-58034 | Fortinet FortiWeb OS Command Injection Vulnerability | Fortinet | 6.7 | 55.6% | KEV | 2025-11-18 |
| CVE-2025-48703 | CWP Control Web Panel OS Command Injection Vulnerability | centos-webpanel | 9.0 | 99.7% | KEV | 2025-09-19 |
| CVE-2025-9377 | Authenticated RCE via Parental Control command injection | TP-Link Systems Inc. | 8.6 | 35.8% | KEV | 2025-08-29 |
| CVE-2025-54948 | Trend Micro Apex One OS Command Injection Vulnerability | Trend Micro, Inc. | 9.4 | 23.9% | KEV | 2025-08-05 |
| CVE-2023-39780 | ASUS RT-AX55 Routers OS Command Injection Vulnerability | ASUS | 8.8 | 39.5% | KEV | 2023-09-11 |
| CVE-2024-12987 | DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection | DrayTek | 7.5 | 98.2% | KEV | 2024-12-27 |
| CVE-2024-11120 | GeoVision EOL devices - OS Command Injection | GeoVision | 9.8 | 28.4% | KEV | 2024-11-15 |
| CVE-2024-6047 | GeoVision EOL device - OS Command Injection | GeoVision | 9.8 | 10.1% | KEV | 2024-06-17 |
| CVE-2023-44221 | SonicWall SMA100 Appliances OS Command Injection Vulnerability | SonicWall | 7.2 | 76.3% | KEV | 2023-12-05 |
| CVE-2021-20035 | SonicWall SMA100 Appliances OS Command Injection Vulnerability | SonicWall | 6.5 | 4.2% | KEV | 2021-09-27 |
| CVE-2025-1316 | Edimax IC-7100 IP Camera OS Command Injection | Edimax | 9.8 | 74.5% | KEV | 2025-03-04 |
| CVE-2024-40891 | Zyxel DSL CPE OS Command Injection Vulnerability | Zyxel | 8.8 | 21.7% | KEV | 2025-02-04 |
| CVE-2024-40890 | Zyxel DSL CPE OS Command Injection Vulnerability | Zyxel | 8.8 | 20.7% | KEV | 2025-02-04 |
| CVE-2024-50603 | Aviatrix Controllers OS Command Injection Vulnerability | Aviatrix | 10.0 | 98.5% | KEV | 2025-01-08 |
| CVE-2024-12686 | Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA) | BeyondTrust | 6.6 | 13.7% | KEV | 2024-12-18 |
| CVE-2021-40407 | Reolink RLC-410W IP Camera OS Command Injection Vulnerability | - | 9.1 | 47.6% | KEV | 2022-01-28 |
| CVE-2024-1212 | LoadMaster Pre-Authenticated OS Command Injection | Progress Software | 10.0 | 95.4% | KEV | 2024-02-21 |
| CVE-2024-9474 | PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface | Palo Alto Networks | 6.9 | 94.8% | KEV | 2024-11-18 |
| CVE-2024-9463 | Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure | Palo Alto Networks | 9.9 | 98.5% | KEV | 2024-10-09 |
| CVE-2024-8957 | PTZOptics NDI and SDI Cameras Command Injection via NTP Address Configuration | PTZOptics | 7.2 | 79.7% | KEV | 2024-09-17 |
| CVE-2024-8190 | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | Ivanti | 7.2 | 88.5% | KEV | 2024-09-10 |
| CVE-2024-4577 | Argument Injection in PHP-CGI | PHP Group | 9.8 | 100.0% | KEV | 2024-06-09 |
| CVE-2023-47565 | Legacy VioStor NVR | QNAP Systems Inc. | 8.0 | 73.3% | KEV | 2023-12-08 |
| CVE-2023-27992 | Zyxel Multiple NAS Devices Command Injection Vulnerability | Zyxel | 9.8 | 82.8% | KEV | 2023-06-19 |
| CVE-2023-28771 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | Zyxel | 9.8 | 99.3% | KEV | 2023-04-25 |
| CVE-2022-33891 | Apache Spark shell command injection vulnerability via Spark UI | Apache Software Foundation | 8.8 | 93.2% | KEV | 2022-07-18 |
| CVE-2018-19949 | QNAP NAS File Station Command Injection Vulnerability | QNAP Systems Inc. | 9.8 | 28.6% | KEV | 2020-10-28 |
| CVE-2022-30525 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | Zyxel | 9.8 | 99.9% | KEV | 2022-05-12 |
| CVE-2020-2509 | Command Injection Vulnerability in QTS and QuTS hero | QNAP Systems Inc. | 9.8 | 34.0% | KEV | 2021-04-17 |
| CVE-2020-9054 | ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi | ZyXEL | 9.8 | 100.0% | KEV | 2020-03-04 |
| CVE-2021-21315 | Command Injection Vulnerability | sebhildebrandt | 7.1 | 90.7% | KEV | 2021-02-16 |
| CVE-2019-10149 | Exim Mail Transfer Agent (MTA) Improper Input Validation | exim | 9.0 | 100.0% | KEV | 2019-06-05 |
| CVE-2021-1498 | Cisco HyperFlex HX Command Injection Vulnerabilities | Cisco | 9.8 | 100.0% | KEV | 2021-05-06 |
| CVE-2021-1497 | Cisco HyperFlex HX Command Injection Vulnerabilities | Cisco | 9.8 | 99.9% | KEV | 2021-05-06 |
| CVE-2026-2041 | Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability | Nagios | 7.2 | 73.7% | 2026-02-20 | |
| CVE-2026-2043 | Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability | Nagios | 7.2 | 73.7% | 2026-02-20 | |
| CVE-2026-0652 | Remote Code Execution on TP-Link Tapo C260 by Guest User | TP-Link Systems Inc. | 8.7 | 23.3% | 2026-02-10 | |
| CVE-2026-2131 | XixianLiang HarmonyOS-mcp-server input_text os command injection | XixianLiang | 6.5 | 17.5% | 2026-02-08 | |
| CVE-2026-4480 | Samba: samba: remote code execution in printing subsystem via unescaped job description | Red Hat | 9.0 | 13.9% | 2026-05-26 | |
| CVE-2026-22844 | Zoom Node Deployments - Command Injection | Zoom Communications Inc. | 9.9 | 13.6% | 2026-01-20 | |
| CVE-2026-10727 | - | Ivanti | 7.2 | 13.6% | 2026-06-09 | |
| CVE-2026-33478 | AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection | WWBN | 10.0 | 11.2% | 2026-03-23 | |
| CVE-2026-2184 | Great Developers Certificate Generation System csv.php os command injection | Great Developers | 7.5 | 10.7% | 2026-02-08 | |
| CVE-2026-7608 | TRENDnet TEW-821DAP tools_diagnostic os command injection | TRENDnet | 5.5 | 9.8% | 2026-05-02 | |
| CVE-2026-28517 | openDCIM <= 23.04 OS Command Injection via dot Configuration Parameter | openDCIM | 9.3 | 9.2% | 2026-02-27 | |
| CVE-2026-8263 | Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection | Tenda | 5.8 | 8.7% | 2026-05-11 | |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8259 | Tenda AC6 httpd telnet os command injection | Tenda | 5.8 | 8.3% | 2026-05-11 | |
| CVE-2026-8265 | Tenda AC6 httpd getLogFile get_log_file os command injection | Tenda | 5.8 | 8.3% | 2026-05-11 | |
| CVE-2026-4253 | Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection | Tenda | 5.8 | 8.2% | 2026-03-16 | |
| CVE-2026-6992 | Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection | Linksys | 8.6 | 8.0% | 2026-04-25 | |
| CVE-2026-4558 | Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection | Linksys | 9.0 | 7.8% | 2026-03-22 | |
| CVE-2026-2846 | UTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection | UTT | 8.6 | 7.5% | 2026-02-20 | |
| CVE-2026-2847 | UTT HiPER 520 Web Management formReleaseConnect sub_44EFB4 os command injection | UTT | 8.6 | 7.5% | 2026-02-20 | |
| CVE-2026-2944 | Tosei Online Store Management System ネット店舗管理システム HTTP POST Request monitor.php system os command injection | Tosei | 7.5 | 7.3% | 2026-02-22 | |
| CVE-2026-2952 | Vaelsys HTTP POST Request tree_server.php os command injection | - | 7.5 | 7.3% | 2026-02-22 | |
| CVE-2026-2188 | UTT 进取 521G formPdbUpConfig sub_446B18 os command injection | UTT | 8.6 | 7.2% | 2026-02-08 | |
| CVE-2026-3040 | DrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection | DrayTek | 5.8 | 7.2% | 2026-02-23 | |
| CVE-2026-8985 | Unauthenticated Command Injection | Autel | 10.0 | 7.1% | 2026-07-21 | |
| CVE-2026-1324 | Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection | Sangfor | 9.0 | 7.1% | 2026-01-22 | |
| CVE-2026-8767 | vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection | vercel | 5.0 | 7.0% | 2026-05-17 | |
| CVE-2026-3485 | D-Link DIR-868L SSDP Service sub_1BF84 os command injection | D-Link | 10.0 | 6.7% | 2026-03-03 | |
| CVE-2026-41922 | WDR201A WiFi Extender OS Command Injection via wireless.cgi | Shenzhen Yipu Commercial and Trading Co., Ltd | 9.3 | 6.7% | 2026-05-04 | |
| CVE-2026-2142 | D-Link DIR-823X set_qos sub_420688 os command injection | D-Link | 8.6 | 6.6% | 2026-02-08 | |
| CVE-2026-3101 | Intelbras TIP 635G Ping os command injection | Intelbras | 6.5 | 6.6% | 2026-02-24 | |
| CVE-2026-8264 | Tenda AC6 httpd WifiApScan formWifiApScan os command injection | Tenda | 6.5 | 6.5% | 2026-05-11 | |
| CVE-2026-2081 | D-Link DIR-823X set_password os command injection | D-Link | 5.8 | 6.4% | 2026-02-07 | |
| CVE-2026-5844 | D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection | D-Link | 8.6 | 6.2% | 2026-04-09 | |
| CVE-2026-8271 | D-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection | D-Link | 5.8 | 6.1% | 2026-05-11 | |
| CVE-2026-8272 | D-Link DNS-320 webfile_mgr.cgi chown os command injection | D-Link | 5.8 | 6.0% | 2026-05-11 | |
| CVE-2026-2082 | D-Link DIR-823X set_mac_clone os command injection | D-Link | 5.8 | 5.9% | 2026-02-07 | |
| CVE-2026-2260 | D-Link DCS-931L setSysAdmin os command injection | D-Link | 8.6 | 5.8% | 2026-02-10 | |
| CVE-2026-1448 | D-Link DIR-615 Web Management wiz_policy_3_machine.php os command injection | D-Link | 8.6 | 5.8% | 2026-01-26 | |
| CVE-2026-5351 | Trendnet TEW-657BRM setup.cgi add_wps_client os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5352 | Trendnet TEW-657BRM setup.cgi edit os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5353 | Trendnet TEW-657BRM setup.cgi ping_test os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5354 | Trendnet TEW-657BRM setup.cgi vpn_connect os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-5355 | Trendnet TEW-657BRM setup.cgi vpn_drop os command injection | Trendnet | 6.5 | 5.7% | 2026-04-02 | |
| CVE-2026-7609 | TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection | TRENDnet | 6.5 | 5.7% | 2026-05-02 | |
| CVE-2026-4585 | Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection | Tiandy | 10.0 | 5.7% | 2026-03-23 | |
| CVE-2026-1506 | D-Link DIR-615 MAC Filter Configuration adv_mac_filter.php os command injection | D-Link | 8.6 | 5.6% | 2026-01-28 | |
| CVE-2026-13545 | D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection | D-Link | 9.0 | 5.5% | 2026-06-29 | |
| CVE-2026-2152 | D-Link DIR-615 Web Configuration adv_routing.php os command injection | D-Link | 8.6 | 5.4% | 2026-02-08 | |
| CVE-2026-2151 | D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection | D-Link | 8.6 | 5.3% | 2026-02-08 | |
| CVE-2026-2063 | D-Link DIR-823X Web Management set_ac_server os command injection | D-Link | 5.8 | 5.3% | 2026-02-06 | |
| CVE-2026-2061 | D-Link DIR-823X set_ipv6 sub_424D20 os command injection | D-Link | 5.8 | 5.1% | 2026-02-06 | |
| CVE-2026-1505 | D-Link DIR-615 URL Filter set_temp_nodes.php os command injection | D-Link | 8.6 | 5.1% | 2026-01-28 | |
| CVE-2026-2129 | D-Link DIR-823X set_ac_status os command injection | D-Link | 8.6 | 5.0% | 2026-02-08 | |
| CVE-2026-2143 | D-Link DIR-823X DDNS Service set_ddns os command injection | D-Link | 8.6 | 5.0% | 2026-02-08 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is OS command injection (CWE-78)?→
It is a weakness where outside input reaches an operating system command without neutralization of special elements. The input can then change which command runs or what it does.
Does a sandbox fully prevent OS command injection?→
No. MITRE rates sandboxing as limited in effectiveness because it only restricts impact on the operating system, so the input handling still needs a fix.
How many exploited vulnerabilities are classified as CWE-78?→
This database lists 111 CVE records mapped to CWE-78 by their CVE Numbering Authority. 48 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 4 to known ransomware campaigns. Examples include CVE-2026-83549, CVE-2026-49869, CVE-2026-73570.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.