Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Systeminformation

First CVE: Oct 26, 2020Active for: 6 yearsTotal CVEs: 11
80.8
VTI Score
TOP TARGET

Systeminformation is a widely embedded Node.js library for retrieving system and hardware information, deployed across a significant range of applications and monitoring tools despite its narrow product scope. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and have a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the elevated risk when OS and command injection flaws occur in a supply-chain dependency. The recurring exposure centers on improper neutralization of special elements in OS and shell commands, improper input validation, and data mutation issues that arise from the library's direct interaction with system-level operations. Defenders should audit downstream products that bundle this library and prioritize remediation for injection vulnerabilities; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked vendors
9.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Systeminformation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2020
5 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-21315HIGH
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In
Feb 16, 20217.896YESYES
CVE-2025-68154HIGH
systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injecti
Dec 16, 20258.135NONO
CVE-2020-26300CRITICAL
systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerabili
Sep 9, 20219.831NONO
CVE-2020-26245CRITICAL
npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to av
Nov 27, 20209.831NONO
CVE-2026-26280HIGH
systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an atta
Feb 19, 20267.830NONO
CVE-2023-42810CRITICAL
systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter che
Sep 21, 20239.830NONO
CVE-2026-26318HIGH
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`.
Feb 19, 20268.829NONO
CVE-2021-21388CRITICAL
systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5
Apr 29, 20219.829NONO
CVE-2020-26274HIGH
In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.
Dec 16, 20208.828NONO
CVE-2020-7752HIGH
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript f
Oct 26, 20208.824NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local3 (27.3%)
Network8 (72.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
1 CVE
9.1% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Systeminformation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Systeminformation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Systeminformation's Products

View all 2 CNAs →

Top CWEs