Fallos del tipo CWE-78

4627 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2024-42978CRITICALAn issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a craftedEPSS 1.2%CVE-2024-2359CRITICALImproper Neutralization of Special Elements used in an OS Command in parisneo/lollms-webuiEPSS 1.2%CVE-2021-42081CRITICALAuthenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355EPSS 1.2%CVE-2026-41876HIGHOS Command Injection in R-SOFT DMSEPSS 1.2%CVE-2026-14371HIGHThe Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to PowershelEPSS 1.2%CVE-2025-58062HIGHLSTM-Kirigaya's openmcp-client Vulnerable to RCE in MCP Authorization FlowEPSS 1.2%CVE-2023-23355MEDIUMQTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVREPSS 1.2%CVE-2025-57799HIGHStreamVault can perform remote command executionEPSS 1.2%CVE-2026-16763MEDIUMlocalstack serverless-localstack Configuration index.js os command injectionEPSS 1.2%CVE-2022-40176—A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 1.2%CVE-2022-2253CRITICALDistributed Data Systems WebHMI OS Command InjectionEPSS 1.2%CVE-2023-29412CRITICALCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remEPSS 1.2%CVE-2025-53100HIGHRestDB's Codehooks.io MCP Server Vulnerable to Command InjectionEPSS 1.2%CVE-2026-4620HIGHOS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.EPSS 1.2%CVE-2026-4622HIGHOS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.EPSS 1.2%CVE-2024-8684HIGHOS Command Injection vulnerability in Revolution PiEPSS 1.2%CVE-2020-10603—WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.EPSS 1.2%CVE-2025-5277CRITICALaws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run aEPSS 1.2%CVE-2025-8613HIGHVacron Camera ping Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-5672HIGHRed Lion Europe: mbNET.mini vulnerable to OS command injectionEPSS 1.2%