Fallos del tipo CWE-78

4645 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-9277CRITICALshell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`EPSS 1.0%CVE-2022-25855HIGHAll versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input saniEPSS 1.0%CVE-2026-11845HIGHIEI Integration Corp|iVEC-IEI Virtualization Edge Computer - OS Command InjectionEPSS 1.0%CVE-2024-10119CRITICALSECOM WRTM326 - OS Command InjectionEPSS 1.0%CVE-2022-43646HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2022-43644HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2022-43647HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2022-43645HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2022-43642HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2026-22901MEDIUMQuNetSwitchEPSS 0.9%CVE-2026-0507HIGHOS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDKEPSS 0.9%CVE-2023-26127HIGHAll versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. *EPSS 0.9%CVE-2025-22481HIGHQTS, QuTS heroEPSS 0.9%CVE-2025-8637MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8632MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8636MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8633MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2026-100382CRITICALUnauthenticated remote code execution through wikitext in ExternalDataEPSS 0.9%CVE-2026-17431MEDIUMPDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_forEPSS 0.9%CVE-2025-26389CRITICALA vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does EPSS 0.9%