Fallos del tipo CWE-78

4603 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2022-1360HIGHCambium Networks cnMaestro OS Command InjectionEPSS 1.9%CVE-2026-34387MEDIUMFleet vulnerable to OS command injection via crafted software package metadata in uninstall scriptsEPSS 1.8%CVE-2021-20017—A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobodEPSS 1.8%CVE-2026-4157HIGHChargePoint Home Flex revssh Service Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2025-59157CRITICALCoolify has Git Repository RCEEPSS 1.8%CVE-2025-63414CRITICALA Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary comEPSS 1.8%CVE-2024-37066MEDIUMA command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary coEPSS 1.8%CVE-2022-1884CRITICALRemote Command Execution in gogs/gogsEPSS 1.8%CVE-2025-44960HIGHRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.EPSS 1.8%CVE-2022-3226HIGHAn OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older thanEPSS 1.8%CVE-2021-47816MEDIUMThecus N4800Eco Nas Server Control Panel - Command InjectionEPSS 1.8%CVE-2024-44341HIGHD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parametEPSS 1.8%CVE-2020-2508HIGHCommand Injection Vulnerability in QTS and QuTS heroEPSS 1.8%CVE-2024-12985MEDIUMOvertek OT-E801G passwd os command injectionEPSS 1.8%CVE-2021-41254HIGHPrivilege escalation to cluster admin on multi-tenant environmentsEPSS 1.8%CVE-2026-0759CRITICALKatana Network Development Starter Kit executeCommand Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2024-43648CRITICALAuthenticated command injection via <redacted>.exe <redacted> parameterEPSS 1.8%CVE-2022-43184CRITICALD-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.EPSS 1.8%CVE-2019-1896HIGHCisco Integrated Management Controller CSR Generation Command Injection VulnerabilityEPSS 1.8%CVE-2019-5072HIGHAn exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart DualEPSS 1.8%