Fallos del tipo CWE-78

4603 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-18590MEDIUMWavlink WL-NU516U1 Admin Password adm.cgi set_sys_adm os command injectionEPSS 1.8%CVE-2026-7642MEDIUMpskill9 website-downloader MCP index.ts download_website os command injectionEPSS 1.8%CVE-2026-7600MEDIUMArtMin96 yii2-mcp-server MCP index.ts yii_execute_command os command injectionEPSS 1.8%CVE-2026-6141MEDIUMdanielmiessler Personal_AI_Infrastructure parse_url.ts os command injectionEPSS 1.8%CVE-2026-91853MEDIUMTOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injectionEPSS 1.8%CVE-2026-90621MEDIUMipa-lab HackingBuddyGPT ssh_run_command.py ssh_run_command os command injectionEPSS 1.8%CVE-2026-79623MEDIUMFishCodeTech Muteki Default Local Worker Backend settings.json os command injectionEPSS 1.8%CVE-2026-5831MEDIUMAgions taskflow-ai terminal_execute handlers.ts os command injectionEPSS 1.8%CVE-2026-15033MEDIUMchristopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injectionEPSS 1.8%CVE-2026-7730MEDIUMprivsim mcp-test-runner MCP index.ts child_process.spawn os command injectionEPSS 1.8%CVE-2026-15513MEDIUMWavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injectionEPSS 1.8%CVE-2022-44252CRITICALTOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.EPSS 1.8%CVE-2022-44249CRITICALTOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.EPSS 1.8%CVE-2021-28804—Command Injection Vulnerabilities in QTS and QuTS heroEPSS 1.8%CVE-2022-44250CRITICALTOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.EPSS 1.8%CVE-2022-44251CRITICALTOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.EPSS 1.8%CVE-2021-28802—Command Injection Vulnerabilities in QTS and QuTS heroEPSS 1.8%CVE-2021-1538MEDIUMCisco Common Services Platform Collector Command Injection VulnerabilityEPSS 1.8%CVE-2025-44882CRITICALA command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary coEPSS 1.8%CVE-2025-44880CRITICALA command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commandEPSS 1.8%