Weaknesses of type CWE-78

4,622 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-80143CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom readEPSS 1.5%CVE-2022-44606HIGHOS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authEPSS 1.5%CVE-2022-24388HIGHAuthenticated Privileged Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.5%CVE-2026-0631HIGHCommand Injection Vulnerability in OpenVPN Modules in Archer BE230, BE3600 and AXE75EPSS 1.5%CVE-2022-24389HIGHAuthenticated Privileged Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.5%CVE-2026-80144CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom writeEPSS 1.5%CVE-2026-23759HIGHPerle IOLAN STS/SCS Authenticated Command Injection via 'shell ps'EPSS 1.5%CVE-2022-46304HIGHChangingTec ServiSign - Command InjectionEPSS 1.5%CVE-2024-57024MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiEPSS 1.5%CVE-2024-52010HIGHZoraxy has an authenticated command injection in the Web SSH featureEPSS 1.5%CVE-2024-42503HIGHAuthenticated Remote Command Execution (RCE) Vulnerability in the Lua Package Within the AOS Command Line Interface (CLI)EPSS 1.5%CVE-2026-5208HIGHImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in coolercontroldEPSS 1.5%CVE-2024-37626HIGHA command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the ifaceEPSS 1.5%CVE-2026-61409HIGHDell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements useEPSS 1.5%CVE-2023-25607HIGHAn improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 EPSS 1.5%CVE-2024-27521HIGHTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multipEPSS 1.5%CVE-2023-23367MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.5%CVE-2022-41955HIGHAutolab is vulnerable to remote code execution (RCE) via MOSS functionalityEPSS 1.5%CVE-2023-32350HIGH Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in aEPSS 1.5%CVE-2026-24252HIGHNVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability EPSS 1.5%