Falhas do tipo CWE-78
4.613 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2020-2028HIGHPAN-OS: OS command injection vulnerability in FIPS-CC mode certificate verificationEPSS 1.8%CVE-2026-71931HIGHDrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeEPSS 1.8%CVE-2026-71913HIGHDrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgiEPSS 1.8%CVE-2021-4281MEDIUMBrave UX for-the-badge combine-prs.yml os command injectionEPSS 1.8%CVE-2005-10003MEDIUMmikexstudios Xcomic os command injectionEPSS 1.8%CVE-2024-50569MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allowsEPSS 1.8%CVE-2024-43649CRITICALAuthenticated command injection via <redacted>.exe <redacted> parameterEPSS 1.8%CVE-2021-3050HIGHPAN-OS: OS Command Injection Vulnerability in Web InterfaceEPSS 1.8%CVE-2023-48667HIGH
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in EPSS 1.8%CVE-2024-9140CRITICALMoxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulneEPSS 1.8%CVE-2020-26294HIGHExposure of server configurationEPSS 1.8%CVE-2026-26355MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 1.8%CVE-2023-49038HIGHCommand injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto tEPSS 1.8%CVE-2026-15485MEDIUMTRENDnet TEW-821DAP DNS Lookup tools_nslookup sub_43F2C4 os command injectionEPSS 1.8%CVE-2026-15547MEDIUMShibby Tomato CIFS Mount sub_2D048 os command injectionEPSS 1.8%CVE-2026-9533MEDIUMTotolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injectionEPSS 1.8%CVE-2026-9511MEDIUMTotolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injectionEPSS 1.8%CVE-2026-19981MEDIUMGL.iNet XE3000 Wi-Fi Timer Power-Schedule Feature os command injectionEPSS 1.8%CVE-2026-7653MEDIUMr-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injectionEPSS 1.8%CVE-2026-15546MEDIUMShibby Tomato start_jffs2 sub_2D568 os command injectionEPSS 1.8%