Fallos del tipo CWE-78

4623 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2023-27991HIGHThe post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEXEPSS 1.5%CVE-2020-36910HIGHCayin Signage Media Player 3.0 Authenticated Remote Command Injection via NTP ParameterEPSS 1.5%CVE-2023-40069CRITICALOS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS cEPSS 1.5%CVE-2026-40527HIGHradare2 Command Injection via DWARF Parameter NamesEPSS 1.5%CVE-2026-81937HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 1.5%CVE-2026-84071HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 1.5%CVE-2025-49141HIGHHaxCMS-PHP Command Injection VulnerabilityEPSS 1.5%CVE-2021-34349HIGHCommand Injection Vulnerability in QVREPSS 1.5%CVE-2021-28811HIGHVulnerability in Roon ServerEPSS 1.5%CVE-2026-31177CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinEPSS 1.4%CVE-2026-31178CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxEPSS 1.4%CVE-2026-31181CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunSerEPSS 1.4%CVE-2026-6721CRITICALMultiple Vulnerabilities in IBM Concert SoftwareEPSS 1.4%CVE-2020-7879HIGHipTIME C200 IP Camera command injection vulnerabilityEPSS 1.4%CVE-2026-27650HIGHOS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may EPSS 1.4%CVE-2025-8078HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmwaEPSS 1.4%CVE-2026-92580HIGHAVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRFEPSS 1.4%CVE-2026-93533MEDIUMspatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injectionEPSS 1.4%CVE-2024-4582HIGHFaraday GM8181/GM828x NTP Service os command injectionEPSS 1.4%CVE-2023-6437CRITICALAuthenticated RCEEPSS 1.4%