Weaknesses of type CWE-78

4,609 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-0783HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0782HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2021-3617HIGHA vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted networEPSS 1.7%CVE-2026-0796HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-95660MEDIUMMoonshot AI Kimi Code MCP Configuration Loader config-loader.ts os command injectionEPSS 1.7%CVE-2024-55020CRITICALA command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attEPSS 1.7%CVE-2026-94106HIGHgetID3 before 1.9.26 OS Command Injection via Unescaped FilenamesEPSS 1.7%CVE-2024-42737CRITICALIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. AuEPSS 1.7%CVE-2024-42748CRITICALIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. AEPSS 1.7%CVE-2025-56099HIGHOS Command Injection vulnerability in Ruijie RG-YST AP_3.0(1)B11P280YST250F allowing attackers to execute arbitrary commands via a crafted PEPSS 1.7%CVE-2025-56113HIGHOS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commaEPSS 1.7%CVE-2026-40519HIGHNginx Proxy Manager Authenticated RCE via setupCertbotPlugins()EPSS 1.7%CVE-2026-44098HIGHOS Command Injection in OCPP Agent via charge_box_idEPSS 1.7%CVE-2026-73767HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 1.7%CVE-2025-25067CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.7%CVE-2024-48889HIGHAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager versionEPSS 1.7%CVE-2026-48695HIGHFastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _loEPSS 1.7%CVE-2023-54339CRITICALWebgrind 1.1 - Remote Command Execution (RCE) via dataFile ParameterEPSS 1.7%CVE-2026-80151CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs downloadEPSS 1.7%CVE-2026-80152CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set script scheduleEPSS 1.7%