Skip to main content

About CWE-78

Unauthorized OS commands can disable the product or read and modify data the attacker could not reach directly. Because the application runs the commands, the activity appears to come from the application or its owner.

MITRE name
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Stable
Also known as
Shell injection, Shell metacharacters, OS Command Injection

Mitigations

  • +Replace calls to external processes with library functions that provide the same behavior.
  • +Use structured mechanisms that keep data separate from the command, such as APIs that take arguments as a list.
  • +Keep data used to build commands out of external control, for example by holding it in server-side session state.
  • +Quote arguments and escape special characters when dynamic commands cannot be avoided, using a strict allowlist.
  • +Run the code in a sandbox such as a chroot jail, AppArmor or SELinux to limit which commands and files are reachable.

Detection
Automated static analysis can often find this weakness through data flow analysis, and dynamic testing with fuzzing has moderate effectiveness according to MITRE.

CWE-78 Vulnerabilities

111 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-83549
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
SonicWall7.810.8%KEV2026-09-01
CVE-2026-49869
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
kestra-io10.02.1%KEV2026-06-26
CVE-2026-73570
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Zimbra8.971.7%KEV2026-08-13
CVE-2026-16812
VeloCloud Orchestrator OS Command Injection
Arista Networks10.01.0%KEV2026-07-27
CVE-2026-25089
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet9.176.1%KEV2026-06-09
CVE-2026-39808
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet9.147.4%KEV2026-04-14
CVE-2025-67038
Lantronix EDS5000, G520, and X300 OS Command Injection
Lantronix9.820.0%KEV2026-03-11
CVE-2026-10520
Ivanti Sentry OS Command Injection Vulnerability
ivanti10.099.9%KEV2026-06-09
CVE-2026-42271
LiteLLM: Authenticated command execution via MCP stdio test endpoints
BerriAI8.792.6%KEV2026-05-08
CVE-2026-25108
Soliton Systems K.K FileZen OS Command Injection Vulnerability
Soliton Systems K.K.8.85.2%KEV2026-02-13
CVE-2026-1731
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
BeyondTrust9.990.9%KEV2026-02-06
CVE-2025-11953
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
-9.894.0%KEV2025-11-03
CVE-2025-64328
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
FreePBX8.684.6%KEV2025-11-07
CVE-2025-66644
Array Networks ArrayOS AG OS Command Injection Vulnerability
Array Networks7.23.4%KEV2025-12-05
CVE-2025-58034
Fortinet FortiWeb OS Command Injection Vulnerability
Fortinet6.755.6%KEV2025-11-18
CVE-2025-48703
CWP Control Web Panel OS Command Injection Vulnerability
centos-webpanel9.099.7%KEV2025-09-19
CVE-2025-9377
Authenticated RCE via Parental Control command injection
TP-Link Systems Inc.8.635.8%KEV2025-08-29
CVE-2025-54948
Trend Micro Apex One OS Command Injection Vulnerability
Trend Micro, Inc.9.423.9%KEV2025-08-05
CVE-2023-39780
ASUS RT-AX55 Routers OS Command Injection Vulnerability
ASUS8.839.5%KEV2023-09-11
CVE-2024-12987
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
DrayTek7.598.2%KEV2024-12-27
CVE-2024-11120
GeoVision EOL devices - OS Command Injection
GeoVision9.828.4%KEV2024-11-15
CVE-2024-6047
GeoVision EOL device - OS Command Injection
GeoVision9.810.1%KEV2024-06-17
CVE-2023-44221
SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall7.276.3%KEV2023-12-05
CVE-2021-20035
SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall6.54.2%KEV2021-09-27
CVE-2025-1316
Edimax IC-7100 IP Camera OS Command Injection
Edimax9.874.5%KEV2025-03-04
CVE-2024-40891
Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel8.821.7%KEV2025-02-04
CVE-2024-40890
Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel8.820.7%KEV2025-02-04
CVE-2024-50603
Aviatrix Controllers OS Command Injection Vulnerability
Aviatrix10.098.5%KEV2025-01-08
CVE-2024-12686
Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)
BeyondTrust6.613.7%KEV2024-12-18
CVE-2021-40407
Reolink RLC-410W IP Camera OS Command Injection Vulnerability
-9.147.6%KEV2022-01-28
CVE-2024-1212
LoadMaster Pre-Authenticated OS Command Injection
Progress Software10.095.4%KEV2024-02-21
CVE-2024-9474
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Palo Alto Networks6.994.8%KEV2024-11-18
CVE-2024-9463
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
Palo Alto Networks9.998.5%KEV2024-10-09
CVE-2024-8957
PTZOptics NDI and SDI Cameras Command Injection via NTP Address Configuration
PTZOptics7.279.7%KEV2024-09-17
CVE-2024-8190
Ivanti Cloud Services Appliance OS Command Injection Vulnerability
Ivanti7.288.5%KEV2024-09-10
CVE-2024-4577
Argument Injection in PHP-CGI
PHP Group9.8100.0%KEV2024-06-09
CVE-2023-47565
Legacy VioStor NVR
QNAP Systems Inc.8.073.3%KEV2023-12-08
CVE-2023-27992
Zyxel Multiple NAS Devices Command Injection Vulnerability
Zyxel9.882.8%KEV2023-06-19
CVE-2023-28771
Zyxel Multiple Firewalls OS Command Injection Vulnerability
Zyxel9.899.3%KEV2023-04-25
CVE-2022-33891
Apache Spark shell command injection vulnerability via Spark UI
Apache Software Foundation8.893.2%KEV2022-07-18
CVE-2018-19949
QNAP NAS File Station Command Injection Vulnerability
QNAP Systems Inc.9.828.6%KEV2020-10-28
CVE-2022-30525
Zyxel Multiple Firewalls OS Command Injection Vulnerability
Zyxel9.899.9%KEV2022-05-12
CVE-2020-2509
Command Injection Vulnerability in QTS and QuTS hero
QNAP Systems Inc.9.834.0%KEV2021-04-17
CVE-2020-9054
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
ZyXEL9.8100.0%KEV2020-03-04
CVE-2021-21315
Command Injection Vulnerability
sebhildebrandt7.190.7%KEV2021-02-16
CVE-2019-10149
Exim Mail Transfer Agent (MTA) Improper Input Validation
exim9.0100.0%KEV2019-06-05
CVE-2021-1498
Cisco HyperFlex HX Command Injection Vulnerabilities
Cisco9.8100.0%KEV2021-05-06
CVE-2021-1497
Cisco HyperFlex HX Command Injection Vulnerabilities
Cisco9.899.9%KEV2021-05-06
CVE-2026-2041
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability
Nagios7.273.7%2026-02-20
CVE-2026-2043
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability
Nagios7.273.7%2026-02-20
CVE-2026-0652
Remote Code Execution on TP-Link Tapo C260 by Guest User
TP-Link Systems Inc.8.723.3%2026-02-10
CVE-2026-2131
XixianLiang HarmonyOS-mcp-server input_text os command injection
XixianLiang6.517.5%2026-02-08
CVE-2026-4480
Samba: samba: remote code execution in printing subsystem via unescaped job description
Red Hat9.013.9%2026-05-26
CVE-2026-22844
Zoom Node Deployments - Command Injection
Zoom Communications Inc.9.913.6%2026-01-20
CVE-2026-10727
-
Ivanti7.213.6%2026-06-09
CVE-2026-33478
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
WWBN10.011.2%2026-03-23
CVE-2026-2184
Great Developers Certificate Generation System csv.php os command injection
Great Developers7.510.7%2026-02-08
CVE-2026-7608
TRENDnet TEW-821DAP tools_diagnostic os command injection
TRENDnet5.59.8%2026-05-02
CVE-2026-28517
openDCIM <= 23.04 OS Command Injection via dot Configuration Parameter
openDCIM9.39.2%2026-02-27
CVE-2026-8263
Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection
Tenda5.88.7%2026-05-11
CVE-2026-8188
Wavlink NU516U1 adm.cgi change_wifi_password os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8189
Wavlink NU516U1 adm.cgi wzdrepeater os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8190
Wavlink NU516U1 adm.cgi wan os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8191
Wavlink NU516U1 adm.cgi wifi_region os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8192
Wavlink NU516U1 adm.cgi wzdap os command injection
Wavlink6.58.5%2026-05-09
CVE-2026-8227
Wavlink NU516U1 adm.cgi wzdapMesh os command injection
Wavlink6.58.5%2026-05-10
CVE-2026-8228
Wavlink NU516U1 wireless.cgi advance os command injection
Wavlink6.58.5%2026-05-10
CVE-2026-8229
Wavlink NU516U1 wireless.cgi WifiBasic os command injection
Wavlink6.58.5%2026-05-10
CVE-2026-8230
Wavlink NU516U1 login.cgi sys_login1 os command injection
Wavlink6.58.5%2026-05-10
CVE-2026-8259
Tenda AC6 httpd telnet os command injection
Tenda5.88.3%2026-05-11
CVE-2026-8265
Tenda AC6 httpd getLogFile get_log_file os command injection
Tenda5.88.3%2026-05-11
CVE-2026-4253
Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection
Tenda5.88.2%2026-03-16
CVE-2026-6992
Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection
Linksys8.68.0%2026-04-25
CVE-2026-4558
Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection
Linksys9.07.8%2026-03-22
CVE-2026-2846
UTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection
UTT8.67.5%2026-02-20
CVE-2026-2847
UTT HiPER 520 Web Management formReleaseConnect sub_44EFB4 os command injection
UTT8.67.5%2026-02-20
CVE-2026-2944
Tosei Online Store Management System ネット店舗管理システム HTTP POST Request monitor.php system os command injection
Tosei7.57.3%2026-02-22
CVE-2026-2952
Vaelsys HTTP POST Request tree_server.php os command injection
-7.57.3%2026-02-22
CVE-2026-2188
UTT 进取 521G formPdbUpConfig sub_446B18 os command injection
UTT8.67.2%2026-02-08
CVE-2026-3040
DrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection
DrayTek5.87.2%2026-02-23
CVE-2026-8985
Unauthenticated Command Injection
Autel10.07.1%2026-07-21
CVE-2026-1324
Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection
Sangfor9.07.1%2026-01-22
CVE-2026-8767
vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection
vercel5.07.0%2026-05-17
CVE-2026-3485
D-Link DIR-868L SSDP Service sub_1BF84 os command injection
D-Link10.06.7%2026-03-03
CVE-2026-41922
WDR201A WiFi Extender OS Command Injection via wireless.cgi
Shenzhen Yipu Commercial and Trading Co., Ltd9.36.7%2026-05-04
CVE-2026-2142
D-Link DIR-823X set_qos sub_420688 os command injection
D-Link8.66.6%2026-02-08
CVE-2026-3101
Intelbras TIP 635G Ping os command injection
Intelbras6.56.6%2026-02-24
CVE-2026-8264
Tenda AC6 httpd WifiApScan formWifiApScan os command injection
Tenda6.56.5%2026-05-11
CVE-2026-2081
D-Link DIR-823X set_password os command injection
D-Link5.86.4%2026-02-07
CVE-2026-5844
D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection
D-Link8.66.2%2026-04-09
CVE-2026-8271
D-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection
D-Link5.86.1%2026-05-11
CVE-2026-8272
D-Link DNS-320 webfile_mgr.cgi chown os command injection
D-Link5.86.0%2026-05-11
CVE-2026-2082
D-Link DIR-823X set_mac_clone os command injection
D-Link5.85.9%2026-02-07
CVE-2026-2260
D-Link DCS-931L setSysAdmin os command injection
D-Link8.65.8%2026-02-10
CVE-2026-1448
D-Link DIR-615 Web Management wiz_policy_3_machine.php os command injection
D-Link8.65.8%2026-01-26
CVE-2026-5351
Trendnet TEW-657BRM setup.cgi add_wps_client os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-5352
Trendnet TEW-657BRM setup.cgi edit os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-5353
Trendnet TEW-657BRM setup.cgi ping_test os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-5354
Trendnet TEW-657BRM setup.cgi vpn_connect os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-5355
Trendnet TEW-657BRM setup.cgi vpn_drop os command injection
Trendnet6.55.7%2026-04-02
CVE-2026-7609
TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection
TRENDnet6.55.7%2026-05-02
CVE-2026-4585
Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection
Tiandy10.05.7%2026-03-23
CVE-2026-1506
D-Link DIR-615 MAC Filter Configuration adv_mac_filter.php os command injection
D-Link8.65.6%2026-01-28
CVE-2026-13545
D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
D-Link9.05.5%2026-06-29
CVE-2026-2152
D-Link DIR-615 Web Configuration adv_routing.php os command injection
D-Link8.65.4%2026-02-08
CVE-2026-2151
D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection
D-Link8.65.3%2026-02-08
CVE-2026-2063
D-Link DIR-823X Web Management set_ac_server os command injection
D-Link5.85.3%2026-02-06
CVE-2026-2061
D-Link DIR-823X set_ipv6 sub_424D20 os command injection
D-Link5.85.1%2026-02-06
CVE-2026-1505
D-Link DIR-615 URL Filter set_temp_nodes.php os command injection
D-Link8.65.1%2026-01-28
CVE-2026-2129
D-Link DIR-823X set_ac_status os command injection
D-Link8.65.0%2026-02-08
CVE-2026-2143
D-Link DIR-823X DDNS Service set_ddns os command injection
D-Link8.65.0%2026-02-08

Frequently Asked Questions

What is OS command injection (CWE-78)?→

It is a weakness where outside input reaches an operating system command without neutralization of special elements. The input can then change which command runs or what it does.

Does a sandbox fully prevent OS command injection?→

No. MITRE rates sandboxing as limited in effectiveness because it only restricts impact on the operating system, so the input handling still needs a fix.

How many exploited vulnerabilities are classified as CWE-78?→

This database lists 111 CVE records mapped to CWE-78 by their CVE Numbering Authority. 48 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 4 to known ransomware campaigns. Examples include CVE-2026-83549, CVE-2026-49869, CVE-2026-73570.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.