Falhas do tipo CWE-78
4.616 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-11900CRITICALHGiga|iSherlock - OS Command InjectionEPSS 1.8%CVE-2023-3267CRITICALWhen adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passeEPSS 1.8%CVE-2023-37927HIGHThe improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwareEPSS 1.8%CVE-2026-4408CRITICALSamba: remote code execution in samrEPSS 1.8%CVE-2024-2662HIGHUnlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command InjectionEPSS 1.7%CVE-2019-5071HIGHAn exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart DualEPSS 1.7%CVE-2022-41131HIGHApache Airflow Hive Provider vulnerability (command injection via hive_cli connection)EPSS 1.7%CVE-2025-34132CRITICALLILIN DVR Command Injection via NTPUpdate in dvr_boxEPSS 1.7%CVE-2024-52034CRITICALmySCADA myPRO OS Command InjectionEPSS 1.7%CVE-2020-8007CRITICALThe pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via thEPSS 1.7%CVE-2021-32524CRITICALQSAN Storage Manager - Command Injection-3EPSS 1.7%CVE-2025-34239HIGHAdvantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction()EPSS 1.7%CVE-2023-39295HIGHQuMagieEPSS 1.7%CVE-2024-57011HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScEPSS 1.7%CVE-2025-34042CRITICALBeward N100 IP Camera Remote Command ExecutionEPSS 1.7%CVE-2026-87911CRITICALRead-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-serverEPSS 1.7%CVE-2024-48826HIGHTenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.EPSS 1.7%CVE-2024-48825HIGHTenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.EPSS 1.7%CVE-2022-4643MEDIUMdocconv pdf_ocr.go ConvertPDFImages os command injectionEPSS 1.7%CVE-2023-48662HIGH
Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%