Fallos del tipo CWE-78

4646 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-8646MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-9661HIGHOS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23/24/26/28EPSS 0.9%CVE-2025-8644MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8648MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-23237MEDIUMImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE aEPSS 0.9%CVE-2026-42215HIGHGitPython: Command injection via Git options bypassEPSS 0.9%CVE-2025-8643MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2022-48070HIGHPhicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade fEPSS 0.9%CVE-2025-69269HIGHSpectrum command injection in NCM serviceEPSS 0.9%CVE-2025-15101HIGHAn OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administratoEPSS 0.9%CVE-2022-48072HIGHPhicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade funEPSS 0.9%CVE-2024-5670CRITICALSoftnext Mail SQR Expert and Mail Archiving Expert - OS Command InjectionEPSS 0.9%CVE-2024-47133HIGHUD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administratEPSS 0.9%CVE-2024-22222HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated maliciouEPSS 0.9%CVE-2026-34176HIGHKnowledge Appliance mode iControl REST vulnerabilityEPSS 0.9%CVE-2022-26582HIGHPAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systoolEPSS 0.9%CVE-2025-44015LOWHybridDesk StationEPSS 0.9%CVE-2024-41790CRITICALA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitEPSS 0.9%CVE-2024-41788CRITICALA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitEPSS 0.9%CVE-2023-22304HIGHOS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker EPSS 0.9%