Fallos del tipo CWE-78

4604 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-44880CRITICALA command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commandEPSS 1.8%CVE-2025-51390CRITICALTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsCoEPSS 1.8%CVE-2025-34056CRITICALAVTECH IP camera, DVR, and NVR Devices Authenticated Root Command ExecutionEPSS 1.8%CVE-2025-54135HIGHCursor Agent is vulnerable to prompt injection via MCP Special FilesEPSS 1.8%CVE-2023-30621CRITICALOS command injection in GipsyEPSS 1.8%CVE-2025-29043CRITICALAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234EPSS 1.8%CVE-2023-40582CRITICALCommand Injection Vulnerability in find-execEPSS 1.8%CVE-2026-84285HIGHOS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5EPSS 1.8%CVE-2023-32151MEDIUMD-Link DIR-2640 DestNetwork Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2023-32147MEDIUMD-Link DIR-2640 LocalIPAddress Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2024-44340HIGHD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and sEPSS 1.8%CVE-2022-43550CRITICALA command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows EPSS 1.8%CVE-2026-3227HIGHAuthenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840NEPSS 1.8%CVE-2024-11066HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.8%CVE-2025-1819MEDIUMTenda AC7 1200M telnet TendaTelnet os command injectionEPSS 1.8%CVE-2024-42502HIGHAuthenticated Remote Command Execution (RCE) Vulnerability in the AOS Command Line InterfaceEPSS 1.8%CVE-2025-13284CRITICALThinPLUS|ThinPLUS - OS Command InjectionEPSS 1.8%CVE-2023-5002MEDIUMPgadmin4: remote code execution by an authenticated userEPSS 1.8%CVE-2026-71916HIGHDrayTek VigorSwitch Multiple Models OS Command Injection via commandTableEPSS 1.8%CVE-2021-4281MEDIUMBrave UX for-the-badge combine-prs.yml os command injectionEPSS 1.8%