Fallos del tipo CWE-78

4627 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-28279HIGH`osctrl-admin` Vulnerable to OS Command Injection via Environment ConfigurationEPSS 1.3%CVE-2023-40480HIGHNETGEAR RAX30 DHCP Server Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-40479HIGHNETGEAR RAX30 UPnP Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-49329HIGHAnomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This aEPSS 1.3%CVE-2025-37172HIGHAuthenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceEPSS 1.3%CVE-2024-28048CRITICALOS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS cEPSS 1.3%CVE-2022-44201CRITICALD-Link DIR823G 1.02B05 is vulnerable to Commad Injection.EPSS 1.3%CVE-2026-26318HIGHsysteminformation has Command Injection via Unsanitized `locate` Output in `versions()`EPSS 1.3%CVE-2018-25118CRITICALGeoVision Command Injection RCE via /PictureCatch.cgiEPSS 1.3%CVE-2026-35018HIGHNetComm NF20MESH < R6B032 Authenticated RCE via OS Command InjectionEPSS 1.3%CVE-2021-34362HIGHCommand Injection Vulnerability in Media Streaming Add-onEPSS 1.3%CVE-2026-49959HIGHHermes WebUI < 0.51.311 RCE via Git Configuration InjectionEPSS 1.3%CVE-2023-3260HIGHThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parametEPSS 1.3%CVE-2025-54763HIGHFutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the EPSS 1.3%CVE-2025-53508HIGHMultiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executEPSS 1.3%CVE-2023-35722HIGHNETGEAR RAX30 UPnP Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-26039HIGHZoneMinder vulnerable to OS Command injection in daemonControl() APIEPSS 1.3%CVE-2024-22423HIGHyt-dlp `--exec` command injection when using `%q` in yt-dlp on WindowsEPSS 1.3%CVE-2025-66576HIGHRemote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)EPSS 1.3%CVE-2023-4033HIGHOS Command Injection in mlflow/mlflowEPSS 1.3%