Fallos del tipo CWE-78

4612 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2020-4066LOWCommand Injection in Limdu trainBatch functionEPSS 1.6%CVE-2025-26817CRITICALNetwrix Password Secure 9.2.0.32454 allows OS command injection.EPSS 1.6%CVE-2024-42736HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. AuEPSS 1.6%CVE-2024-28187HIGHOS Command Injection Vulnerability in SOY CMSEPSS 1.6%CVE-2026-24517HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.6%CVE-2022-48337CRITICALGNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etagEPSS 1.6%CVE-2024-0714MEDIUMMiczFlor RPi-Jukebox-RFID HTTP Request userScripts.php os command injectionEPSS 1.6%CVE-2024-24331CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiSEPSS 1.6%CVE-2026-11556HIGHTenda F451 Web Management WriteFacMac formWriteFacMac os command injectionEPSS 1.6%CVE-2022-37912HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.6%CVE-2024-3659CRITICALCommand injection in KAON AR2140 routersEPSS 1.6%CVE-2026-45695CRITICALKopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is usedEPSS 1.6%CVE-2026-2035MEDIUMDeciso OPNsense diag_backup.php filename Command Injection Remote Code Execution VulnerabilityEPSS 1.6%CVE-2025-45042CRITICALTenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.EPSS 1.6%CVE-2023-6201HIGHCommand Injection in Univera Panorama FrameworkEPSS 1.6%CVE-2024-45827HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmwareEPSS 1.6%CVE-2024-41153HIGHCommand injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commEPSS 1.6%CVE-2024-43650CRITICALAuthenticated command injection in the <redacted> action leads to full remote code execution as root on the charging stationEPSS 1.6%CVE-2024-57019HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAEPSS 1.6%CVE-2024-57013HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setSchEPSS 1.6%