Fallos del tipo CWE-78

4623 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2022-27647HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.9EPSS 1.5%CVE-2026-24697HIGHAn OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55EPSS 1.5%CVE-2026-24699HIGHAn OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 andEPSS 1.5%CVE-2024-43657CRITICALWhen uploading new firmware, a shell script inside a firmware file is executed during its processing. This can be used to craft a custom firmware file with a custom script with arbitrary code, which will then be executed on the charging station.EPSS 1.5%CVE-2023-42495CRITICAL Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.5%CVE-2023-47802HIGHA vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP blocEPSS 1.5%CVE-2024-48860CRITICALQHoraEPSS 1.5%CVE-2026-75123HIGHPLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_smtp_test_postEPSS 1.5%CVE-2026-75121HIGHPLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postEPSS 1.5%CVE-2024-38887CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 1.5%CVE-2026-0830HIGHCommand Injection in Kiro GitLab Merge Request HelperEPSS 1.5%CVE-2026-22553CRITICALInSAT MasterSCADA BUK-TS OS Command InjectionEPSS 1.5%CVE-2024-51023HIGHD-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySeEPSS 1.5%CVE-2026-92993MEDIUMDromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injectionEPSS 1.5%CVE-2023-28528HIGHIBM AIX command executionEPSS 1.5%CVE-2022-39224HIGHArbitrary shell execution when extracting or listing files contained in a malicious rpm.EPSS 1.5%CVE-2022-37898HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.5%CVE-2025-14287HIGHCommand Injection in mlflow/mlflowEPSS 1.5%CVE-2026-32649HIGHMilesight Cameras OS Command InjectionEPSS 1.5%CVE-2023-51450MEDIUMbaserCMS OS command injection vulnerability in InstallerEPSS 1.5%