Falhas do tipo CWE-78
4.626 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-53688HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 aEPSS 1.6%CVE-2023-33965CRITICALBrook's tproxy server is vulnerable to a drive-by command injection.EPSS 1.6%CVE-2026-58147CRITICALAuthorized remote code execution via password change functionality in T-Mobile 5G Box IDU routersEPSS 1.6%CVE-2024-9166CRITICALOS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite ReceiverEPSS 1.6%CVE-2022-40719HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routerEPSS 1.6%CVE-2022-37880HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.6%CVE-2022-37882HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.6%CVE-2022-3183CRITICALDataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provideEPSS 1.6%CVE-2024-53899HIGHvirtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not EPSS 1.6%CVE-2026-29058CRITICALAVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.phpEPSS 1.6%CVE-2024-36360CRITICALOS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote EPSS 1.6%CVE-2020-15121HIGHCommand injection in Radare2EPSS 1.6%CVE-2023-23692HIGH
Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacker could potentially EPSS 1.6%CVE-2025-32107HIGHOS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vEPSS 1.6%CVE-2022-37924HIGHVulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on theEPSS 1.6%CVE-2026-72573HIGH4xmen pm2panel - Authenticated OS Command Injection via id Query ParameterEPSS 1.6%CVE-2018-25122HIGHNagios XI < 5.4.13 Component Download Page RCEEPSS 1.6%CVE-2024-58314HIGHAtcom 2.7.x.x Authenticated Command Injection via Web Configuration CGIEPSS 1.6%CVE-2022-48584HIGHA command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐contEPSS 1.6%CVE-2026-50206HIGHVPN Command Injection VulnerabilityEPSS 1.6%