Fallos del tipo CWE-78

4664 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-15518HIGHCommand Injection in Wireless Control CLI on TP-Link Archer NX200, NX210, NX500 and NX600EPSS 0.6%CVE-2025-15519HIGHCommand Injection in Modem Management CLI on TP-Link Archer NX200, NX210, NX500 and NX600EPSS 0.6%CVE-2025-52626MEDIUMHCL AION is susceptible to Potential Command Injection vulnerabilityEPSS 0.6%CVE-2023-24046HIGHAn issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in thEPSS 0.6%CVE-2026-42853MEDIUM@apostrophecms/cli: Command Injection in apos create via Unsanitized Password InputEPSS 0.6%CVE-2026-82892HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2021-3934HIGHOS Command Injection in ohmyzsh/ohmyzshEPSS 0.6%CVE-2026-85756HIGHSSH.NET: ScpClient allows server-side RCE via default SCP path handlingEPSS 0.6%CVE-2026-93425CRITICALDokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as rootEPSS 0.6%CVE-2023-44279MEDIUM Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability iEPSS 0.6%CVE-2026-23821HIGHInconsistent input filtering allows Authenticated Command Injection in AOS-10 CLIEPSS 0.6%CVE-2025-41675HIGHRemote Command Injection via GET in Cloud Server Communication Script Due to Improper Input NeutralizationEPSS 0.6%CVE-2025-41674HIGHRemote Command Injection in diagnostic Action Due to Improper Input NeutralizationEPSS 0.6%CVE-2025-41673HIGHRemote Command Injection in send_sms Action Due to Improper Input NeutralizationEPSS 0.6%CVE-2026-73412MEDIUMShescape: Path disclosure on Unix with ZshEPSS 0.6%CVE-2025-29534HIGHAn authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentiaEPSS 0.6%CVE-2023-51699MEDIUMOS Command Injection for Fluid Users with JuicefsRuntimeEPSS 0.6%CVE-2024-45720HIGHApache Subversion: Command line argument injection on Windows platformsEPSS 0.6%CVE-2025-24022HIGHiTop server vulnerable to portal code injectionEPSS 0.6%CVE-2025-64140HIGHJenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with IteEPSS 0.6%