Fallos del tipo CWE-78

4627 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-25828MEDIUMgrub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitizEPSS 1.4%CVE-2023-25925HIGHIBM Security Guardium Key Lifecycle Manager command injectionEPSS 1.4%CVE-2025-34150CRITICALShenzhen Aitemi M300 Wi-Fi Repeater PPPoE Username Command InjectionEPSS 1.4%CVE-2026-40711HIGHDell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contEPSS 1.3%CVE-2022-31486HIGHCommand injection via Advanced Networking route add functionalityEPSS 1.3%CVE-2024-50359HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2026-21571CRITICALThis Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0,EPSS 1.3%CVE-2025-28036CRITICALTOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function EPSS 1.3%CVE-2025-28035CRITICALTOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function tEPSS 1.3%CVE-2025-28034CRITICALTOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000REPSS 1.3%CVE-2024-12970LOWOS Command Injection in TUBITAK BILGEM's Pardus OS My ComputerEPSS 1.3%CVE-2023-40581HIGHyt-dlp command injection when using `%q` in `--exec` on WindowsEPSS 1.3%CVE-2026-65096HIGHNVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. EPSS 1.3%CVE-2021-21412MEDIUM[thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property valuesEPSS 1.3%CVE-2026-65099HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A succEPSS 1.3%CVE-2026-65089HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injectioEPSS 1.3%CVE-2026-0273MEDIUMPAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UIEPSS 1.3%CVE-2024-7203HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firEPSS 1.3%CVE-2024-42060HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmwaEPSS 1.3%CVE-2024-42059HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmwaEPSS 1.3%