Fallos del tipo CWE-78

4603 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-53479HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 2.0%CVE-2026-20764HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 2.0%CVE-2022-44844CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setEPSS 2.0%CVE-2025-15063CRITICALOllama MCP Server execAsync Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2024-5291HIGHD-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2024-5295HIGHD-Link G416 flupl self Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2022-44843CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setEPSS 2.0%CVE-2021-28203HIGHASUS BMC's firmware: command injection - Web Set Media Image functionEPSS 2.0%CVE-2022-48124CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the settingEPSS 2.0%CVE-2022-48126CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the settingEPSS 2.0%CVE-2022-48122CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the settingEPSS 2.0%CVE-2022-48121CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/EPSS 2.0%CVE-2022-48125CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the settingEPSS 2.0%CVE-2022-48123CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the settiEPSS 2.0%CVE-2026-32260HIGHCommand Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)EPSS 2.0%CVE-2026-16348HIGHCommand Injection Vulnerability in VPN connection of Archer BE800EPSS 2.0%CVE-2026-74770HIGHDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS CommanEPSS 2.0%CVE-2005-10004HIGHCacti graph_view.php RCE via graph_start Parameter InjectionEPSS 2.0%CVE-2026-72589CRITICALalseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook FieldEPSS 1.9%CVE-2021-4144—TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.EPSS 1.9%