Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-78 (OS命令中使用的特殊元素转义处理不恰当(OS命令注入)) — Vulnerability Class 2646

2646 vulnerabilities classified as CWE-78 (OS命令中使用的特殊元素转义处理不恰当(OS命令注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-6115 Totolink A7100RU CGI cstecgi.cgi setAppCfg os command injection — A7100RU 9.8 Critical2026-04-12
CVE-2026-6114 Totolink A7100RU CGI cstecgi.cgi setNetworkCfg os command injection — A7100RU 9.8 Critical2026-04-12
CVE-2026-6113 Totolink A7100RU CGI cstecgi.cgi setTtyServiceCfg os command injection — A7100RU 9.8 Critical2026-04-12
CVE-2026-6112 Totolink A7100RU CGI cstecgi.cgi setRadvdCfg os command injection — A7100RU 9.8 Critical2026-04-12
CVE-2026-6108 1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection — MaxKB 6.3 Medium2026-04-12
CVE-2026-4157 ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability — Home Flex 8.8AIHighAI2026-04-11
CVE-2026-5059 aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability — aws-mcp-server 9.8AICriticalAI2026-04-11
CVE-2026-5058 aws-mcp-server Command Injection Remote Code Execution Vulnerability — aws-mcp-server 9.8AICriticalAI2026-04-11
CVE-2026-32892 OS Command Injection in Chamilo LMS 1.11.36 — chamilo-lms 9.1 Critical2026-04-10
CVE-2026-6029 Totolink A7100RU CGI cstecgi.cgi setVpnAccountCfg os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-6028 Totolink A7100RU CGI cstecgi.cgi setPptpServerCfg os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-6027 Totolink A7100RU CGI cstecgi.cgi setUrlFilterRules os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-6026 Totolink A7100RU CGI cstecgi.cgi setPortalConfWeChat os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-6025 Totolink A7100RU CGI cstecgi.cgi setSyslogCfg os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-5997 Totolink A7100RU CGI cstecgi.cgi setLoginPasswordCfg os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-5996 Totolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-5995 Totolink A7100RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-5994 Totolink A7100RU CGI cstecgi.cgi setTelnetCfg os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-5993 Totolink A7100RU CGI cstecgi.cgi setWiFiGuestCfg os command injection — A7100RU 9.8 Critical2026-04-10
CVE-2026-33791 Junos OS and Junos OS Evolved: Execution of crafted CLI commands allows for arbitrary shell injection as root — Junos OS 6.7 Medium2026-04-09
CVE-2026-40111 PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py) — PraisonAIAgents 7.8AIHighAI2026-04-09
CVE-2026-5978 Totolink A7100RU CGI cstecgi.cgi setWiFiAclRules os command injection — A7100RU 9.8 Critical2026-04-09
CVE-2026-5977 Totolink A7100RU CGI cstecgi.cgi setWiFiBasicCfg os command injection — A7100RU 9.8 Critical2026-04-09
CVE-2026-5976 Totolink A7100RU CGI cstecgi.cgi setStorageCfg os command injection — A7100RU 9.8 Critical2026-04-09
CVE-2026-5975 Totolink A7100RU CGI cstecgi.cgi setDmzCfg os command injection — A7100RU 9.8 Critical2026-04-09
CVE-2026-40088 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai — PraisonAI 9.7 Critical2026-04-09
CVE-2026-5974 FoundationAgents MetaGPT terminal.py Bash.run os command injection — MetaGPT 7.3 High2026-04-09
CVE-2026-5973 FoundationAgents MetaGPT common.py get_mime_type os command injection — MetaGPT 7.3 High2026-04-09
CVE-2026-5972 FoundationAgents MetaGPT terminal.py Terminal.run_command os command injection — MetaGPT 7.3 High2026-04-09
CVE-2026-5854 Totolink A7100RU CGI cstecgi.cgi setWiFiEasyCfg os command injection — A7100RU 9.8 Critical2026-04-09

Vulnerabilities classified as CWE-78 (OS命令中使用的特殊元素转义处理不恰当(OS命令注入)) represent 2646 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.