Weaknesses of type CWE-78

4,604 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-7653MEDIUMr-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injectionEPSS 1.8%CVE-2026-15546MEDIUMShibby Tomato start_jffs2 sub_2D568 os command injectionEPSS 1.8%CVE-2026-9565MEDIUMhaojing8312 WorkClaw Blacklist bash.rs is_dangerous os command injectionEPSS 1.8%CVE-2020-2029HIGHPAN-OS: OS command injection vulnerability in management interface certificate generatorEPSS 1.8%CVE-2026-15486MEDIUMTRENDnet TEW-821DAP Firmware Update tools_ddns sub_42026C os command injectionEPSS 1.8%CVE-2026-9514MEDIUMTotolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injectionEPSS 1.8%CVE-2026-36045HIGHpicoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() funcEPSS 1.8%CVE-2026-9531MEDIUMTotolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injectionEPSS 1.8%CVE-2026-9513MEDIUMTotolink CA750-PoE Setting cstecgi.cgi NTPSyncWithHost os command injectionEPSS 1.8%CVE-2026-19982MEDIUMGL.iNet BE9300/MT6000 Firewall-management RPC os command injectionEPSS 1.8%CVE-2026-9534MEDIUMTotolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injectionEPSS 1.8%CVE-2026-9512MEDIUMTotolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injectionEPSS 1.8%CVE-2026-15547MEDIUMShibby Tomato CIFS Mount sub_2D048 os command injectionEPSS 1.8%CVE-2026-15485MEDIUMTRENDnet TEW-821DAP DNS Lookup tools_nslookup sub_43F2C4 os command injectionEPSS 1.8%CVE-2026-22550HIGHOS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary EPSS 1.8%CVE-2026-38061CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.EPSS 1.8%CVE-2026-13206CRITICALMultiple Vulnerabilities in Zyxel's WAH7601 - OS Command InjectionEPSS 1.8%CVE-2026-38065CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.EPSS 1.8%CVE-2026-38063CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.EPSS 1.8%CVE-2026-38064CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.EPSS 1.8%