Fallos del tipo CWE-78

4653 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2024-20458HIGHCisco ATA 190 Series Analog Telephone Adapter Software VulnerabilitiesEPSS 0.7%CVE-2026-46483LOWVim: Command injection in tar#Vimuntar via missing shellescape {special} flagEPSS 0.7%CVE-2023-3333—Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG18EPSS 0.7%CVE-2019-3595LOWDLP Endpoint ePO extension not sanitizing CSV exportsEPSS 0.7%CVE-2021-47747HIGHmeterN 1.2.3 Authenticated Remote Code Execution via Admin ScriptsEPSS 0.7%CVE-2025-23316CRITICALNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote EPSS 0.7%CVE-2024-5227HIGHTP-Link Omada ER605 PPTP VPN username Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-33368HIGHAn issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScEPSS 0.7%CVE-2026-72868CRITICALDokploy: Member-role RCE as host root via destination.testConnection rclone shell injectionEPSS 0.7%CVE-2026-72876CRITICALDokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*EPSS 0.7%CVE-2025-53623HIGHJob Iteration API is vulnerable to OS Command Injection attack through its CsvEnumerator classEPSS 0.7%CVE-2026-73447CRITICALSecurity Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate RequestEPSS 0.7%CVE-2026-88276HIGHGV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command InjectionEPSS 0.7%CVE-2026-55157HIGHToken Optimizer MCP: OS command injection in smart_user via username in get-user-infoEPSS 0.7%CVE-2026-88274HIGHGV-LPC2011/LPC2211 - Wireless SSID Command InjectionEPSS 0.7%CVE-2026-88275HIGHGV-LPC2011/LPC2211 - Wireless WPA-PSK Command InjectionEPSS 0.7%CVE-2026-88273HIGHGV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command InjectionEPSS 0.7%CVE-2024-29167HIGHSVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execute arbitrary OS commEPSS 0.7%CVE-2021-0219MEDIUMJunos OS: Command injection vulnerability in 'request system software' CLI commandEPSS 0.7%CVE-2026-45777CRITICALOpen XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command InjectionEPSS 0.7%