Fallos del tipo CWE-78

4609 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-0783HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0782HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2021-3617HIGHA vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted networEPSS 1.7%CVE-2026-0796HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-95660MEDIUMMoonshot AI Kimi Code MCP Configuration Loader config-loader.ts os command injectionEPSS 1.7%CVE-2024-55020CRITICALA command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attEPSS 1.7%CVE-2026-94106HIGHgetID3 before 1.9.26 OS Command Injection via Unescaped FilenamesEPSS 1.7%CVE-2024-42737CRITICALIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. AuEPSS 1.7%CVE-2024-42748CRITICALIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. AEPSS 1.7%CVE-2025-56099HIGHOS Command Injection vulnerability in Ruijie RG-YST AP_3.0(1)B11P280YST250F allowing attackers to execute arbitrary commands via a crafted PEPSS 1.7%CVE-2025-56113HIGHOS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commaEPSS 1.7%CVE-2026-40519HIGHNginx Proxy Manager Authenticated RCE via setupCertbotPlugins()EPSS 1.7%CVE-2026-44098HIGHOS Command Injection in OCPP Agent via charge_box_idEPSS 1.7%CVE-2026-73767HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 1.7%CVE-2025-25067CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.7%CVE-2024-48889HIGHAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager versionEPSS 1.7%CVE-2026-48695HIGHFastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _loEPSS 1.7%CVE-2023-54339CRITICALWebgrind 1.1 - Remote Command Execution (RCE) via dataFile ParameterEPSS 1.7%CVE-2026-80151CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs downloadEPSS 1.7%CVE-2026-80152CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set script scheduleEPSS 1.7%