Falhas do tipo CWE-78
4.616 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-38064CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.EPSS 1.8%CVE-2026-38060CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.EPSS 1.8%CVE-2026-38065CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.EPSS 1.8%CVE-2026-38063CRITICALTenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.EPSS 1.8%CVE-2024-57542HIGHLinksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.EPSS 1.8%CVE-2023-34277MEDIUMD-Link DIR-2150 SetSysEmailSettings AccountName Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2023-34281MEDIUMD-Link DIR-2150 GetFirmwareStatus Target Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2023-34275MEDIUMD-Link DIR-2150 SetNTPServerSettings Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2023-34280MEDIUMD-Link DIR-2150 SetSysEmailSettings EmailTo Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2023-34278MEDIUMD-Link DIR-2150 SetSysEmailSettings EmailFrom Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2023-34276MEDIUMD-Link DIR-2150 SetTriggerPPPoEValidate Username Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2020-35851HIGHHGiga MailSherlock - Command InjectionEPSS 1.8%CVE-2026-47670CRITICALDbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injectionEPSS 1.8%CVE-2023-31756MEDIUMA command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1EPSS 1.8%CVE-2022-37897CRITICALThere is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets desEPSS 1.8%CVE-2022-1357CRITICALCambium Networks cnMaestro OS Command InjectionEPSS 1.8%CVE-2025-8667MEDIUMSkyworkAI DeepResearchAgent tools.py from_mcp os command injectionEPSS 1.8%CVE-2022-40720HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routerEPSS 1.8%CVE-2025-8697MEDIUMagentUniverse MCPSessionManager/MCPTool/MCPToolkit StdioServerParameters os command injectionEPSS 1.8%CVE-2025-8665MEDIUMagno-agi agno Model Context Protocol mcp.py MultiMCPTools os command injectionEPSS 1.8%