Weaknesses of type CWE-78

4,623 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-15568HIGHCommand Injection Vulnerability on TP-Link Archer AXE75EPSS 1.4%CVE-2026-85425CRITICALMOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOSEPSS 1.4%CVE-2022-34374HIGHDell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user EPSS 1.4%CVE-2024-22445HIGH Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remote high privileged aEPSS 1.4%CVE-2025-11730HIGHA post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versiEPSS 1.4%CVE-2024-25955HIGHDell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit thiEPSS 1.4%CVE-2024-25946HIGHDell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit thiEPSS 1.4%CVE-2022-43538HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.4%CVE-2022-43537HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.4%CVE-2026-8652HIGHAn OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, EPSS 1.4%CVE-2024-27124HIGHQTS, QuTS hero, QuTScloudEPSS 1.4%CVE-2024-36060HIGHEnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test paramEPSS 1.4%CVE-2024-39202HIGHD-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter aEPSS 1.4%CVE-2026-26942MEDIUMDell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OSEPSS 1.4%CVE-2021-28800HIGHCommand Injection Vulnerability in QTSEPSS 1.4%CVE-2022-50994CRITICALDrayTek Vigor 2960 < 1.5.1.4 OS Command Injection via mainfunction.cgiEPSS 1.4%CVE-2023-34279MEDIUMD-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2020-11084MEDIUMCommand Injection in iPearEPSS 1.4%CVE-2026-30635HIGHCommand injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka vEPSS 1.4%CVE-2022-29841HIGHOS Command Injection vulnerability in Western Digital My Cloud devicesEPSS 1.4%