Weaknesses of type CWE-78

4,604 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-44880CRITICALA command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commandEPSS 1.8%CVE-2025-51390CRITICALTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsCoEPSS 1.8%CVE-2025-34056CRITICALAVTECH IP camera, DVR, and NVR Devices Authenticated Root Command ExecutionEPSS 1.8%CVE-2025-54135HIGHCursor Agent is vulnerable to prompt injection via MCP Special FilesEPSS 1.8%CVE-2023-30621CRITICALOS command injection in GipsyEPSS 1.8%CVE-2025-29043CRITICALAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234EPSS 1.8%CVE-2023-40582CRITICALCommand Injection Vulnerability in find-execEPSS 1.8%CVE-2026-84285HIGHOS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5EPSS 1.8%CVE-2023-32151MEDIUMD-Link DIR-2640 DestNetwork Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2023-32147MEDIUMD-Link DIR-2640 LocalIPAddress Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2024-44340HIGHD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and sEPSS 1.8%CVE-2022-43550CRITICALA command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows EPSS 1.8%CVE-2026-3227HIGHAuthenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840NEPSS 1.8%CVE-2024-11066HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.8%CVE-2025-1819MEDIUMTenda AC7 1200M telnet TendaTelnet os command injectionEPSS 1.8%CVE-2024-42502HIGHAuthenticated Remote Command Execution (RCE) Vulnerability in the AOS Command Line InterfaceEPSS 1.8%CVE-2025-13284CRITICALThinPLUS|ThinPLUS - OS Command InjectionEPSS 1.8%CVE-2023-5002MEDIUMPgadmin4: remote code execution by an authenticated userEPSS 1.8%CVE-2026-71916HIGHDrayTek VigorSwitch Multiple Models OS Command Injection via commandTableEPSS 1.8%CVE-2021-4281MEDIUMBrave UX for-the-badge combine-prs.yml os command injectionEPSS 1.8%