Fallos del tipo CWE-78

4645 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-6562HIGHHunt Electronic Hybrid DVR - OS Command InjectionEPSS 0.9%CVE-2023-37407HIGHIBM Aspera Orchestrator command executionEPSS 0.9%CVE-2025-30264HIGHQTS, QuTS heroEPSS 0.9%CVE-2026-0709HIGHSome Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers withEPSS 0.9%CVE-2025-59534HIGHCryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login()EPSS 0.9%CVE-2026-58571HIGHDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit thisEPSS 0.9%CVE-2026-58567HIGHDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit thisEPSS 0.9%CVE-2026-35463HIGHpyLoad has Improper Neutralization of Special Elements used in an OS CommandEPSS 0.9%CVE-2026-33208HIGHRoxy-WI Vulnerable to Authenticated Remote Code Execution via OS Command Injection in find-in-config EndpointEPSS 0.9%CVE-2026-35581HIGHEmissary has a Command Injection via PLACE_NAME Configuration in ExecutrixEPSS 0.9%CVE-2026-78177LOWTanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injectionEPSS 0.9%CVE-2026-31994MEDIUMOpenClaw < 2026.2.19 - Local Command Injection via Unsafe cmd Argument Handling in Windows Scheduled Task Script GenerationEPSS 0.9%CVE-2026-26009CRITICALCatalyst Affected by Remote Code Execution as Root via Containerized Install Script ExecutionEPSS 0.9%CVE-2023-6260HIGHWeb UI OS Command Injection in Brivo ACS100, ACS300EPSS 0.9%CVE-2025-9976CRITICALOS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.9%CVE-2024-33529HIGHILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execEPSS 0.9%CVE-2026-25546HIGHGodot MCP is vulnerable to Command Injection via unsanitized projectPathEPSS 0.9%CVE-2025-8644MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8647MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8645MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%