Falhas do tipo CWE-78
4.622 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-35506HIGHELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processinEPSS 1.7%CVE-2026-59764HIGHELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploEPSS 1.7%CVE-2026-61376HIGHELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerabiliEPSS 1.7%CVE-2026-50043HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If thiEPSS 1.7%CVE-2026-49815HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 1.7%CVE-2026-34188HIGHOS Command Injection in Event Response ExecutionEPSS 1.7%CVE-2024-7448HIGHMagnet Forensics AXIOM Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2022-42055MEDIUMMultiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroEPSS 1.7%CVE-2026-16468HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 1.7%CVE-2025-64153MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, EPSS 1.7%CVE-2023-51625HIGHD-Link DCS-8300LHV2 ONVIF SetSystemDateAndTime Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-39091HIGHAn OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers withiEPSS 1.7%CVE-2022-37915CRITICALA vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.7%CVE-2024-4253HIGHCommand Injection in gradio-app/gradioEPSS 1.7%CVE-2026-44170MEDIUMMariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URLEPSS 1.7%CVE-2020-2492HIGHIf exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP SysteEPSS 1.7%CVE-2024-50853HIGHTenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.EPSS 1.7%CVE-2024-50852HIGHTenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.EPSS 1.7%CVE-2024-24333CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclEPSS 1.7%CVE-2012-10033CRITICALNarcissus backend.php Image Configuration Command InjectionEPSS 1.7%