Fallos del tipo CWE-78

4622 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-35506HIGHELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processinEPSS 1.7%CVE-2026-59764HIGHELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploEPSS 1.7%CVE-2026-61376HIGHELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerabiliEPSS 1.7%CVE-2026-50043HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If thiEPSS 1.7%CVE-2026-49815HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 1.7%CVE-2026-34188HIGHOS Command Injection in Event Response ExecutionEPSS 1.7%CVE-2024-7448HIGHMagnet Forensics AXIOM Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2022-42055MEDIUMMultiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroEPSS 1.7%CVE-2026-16468HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 1.7%CVE-2025-64153MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, EPSS 1.7%CVE-2023-51625HIGHD-Link DCS-8300LHV2 ONVIF SetSystemDateAndTime Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-39091HIGHAn OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers withiEPSS 1.7%CVE-2022-37915CRITICALA vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.7%CVE-2024-4253HIGHCommand Injection in gradio-app/gradioEPSS 1.7%CVE-2026-44170MEDIUMMariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URLEPSS 1.7%CVE-2020-2492HIGHIf exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP SysteEPSS 1.7%CVE-2024-50853HIGHTenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.EPSS 1.7%CVE-2024-50852HIGHTenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.EPSS 1.7%CVE-2024-24333CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclEPSS 1.7%CVE-2012-10033CRITICALNarcissus backend.php Image Configuration Command InjectionEPSS 1.7%