Falhas do tipo CWE-78

4.623 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-0782HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0784HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2021-3617HIGHA vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted networEPSS 1.7%CVE-2026-0796HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-95660MEDIUMMoonshot AI Kimi Code MCP Configuration Loader config-loader.ts os command injectionEPSS 1.7%CVE-2024-55020CRITICALA command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attEPSS 1.7%CVE-2026-94106HIGHgetID3 before 1.9.26 OS Command Injection via Unescaped FilenamesEPSS 1.7%CVE-2024-42737CRITICALIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. AuEPSS 1.7%CVE-2024-42748CRITICALIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. AEPSS 1.7%CVE-2025-56099HIGHOS Command Injection vulnerability in Ruijie RG-YST AP_3.0(1)B11P280YST250F allowing attackers to execute arbitrary commands via a crafted PEPSS 1.7%CVE-2025-56113HIGHOS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commaEPSS 1.7%CVE-2026-40519HIGHNginx Proxy Manager Authenticated RCE via setupCertbotPlugins()EPSS 1.7%CVE-2026-44098HIGHOS Command Injection in OCPP Agent via charge_box_idEPSS 1.7%CVE-2026-73767HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 1.7%CVE-2023-54339CRITICALWebgrind 1.1 - Remote Command Execution (RCE) via dataFile ParameterEPSS 1.7%CVE-2025-25067CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.7%CVE-2024-48889HIGHAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager versionEPSS 1.7%CVE-2026-48695HIGHFastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _loEPSS 1.7%CVE-2026-80151CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs downloadEPSS 1.7%CVE-2026-80152CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set script scheduleEPSS 1.7%