Falhas do tipo CWE-78
4.627 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-20910HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2026-20902HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2026-21389HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2023-5037HIGHAuthenticated Command InjectionEPSS 1.5%CVE-2025-34055CRITICALAVTECH IP camera, DVR, and NVR Devices Authenticated Root Command ExecutionEPSS 1.5%CVE-2025-66052HIGHCommand injection in Vivotek IP7137 camerasEPSS 1.5%CVE-2022-44606HIGHOS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authEPSS 1.5%CVE-2026-80143CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom readEPSS 1.5%CVE-2026-80144CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom writeEPSS 1.5%CVE-2026-0631HIGHCommand Injection Vulnerability in OpenVPN Modules in Archer BE230, BE3600 and AXE75EPSS 1.5%CVE-2022-22997MEDIUMCommand Injection Vulnerability on My Cloud HomeEPSS 1.5%CVE-2022-24388HIGHAuthenticated Privileged Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.5%CVE-2022-24389HIGHAuthenticated Privileged Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.5%CVE-2026-23759HIGHPerle IOLAN STS/SCS Authenticated Command Injection via 'shell ps'EPSS 1.5%CVE-2022-46304HIGHChangingTec ServiSign - Command InjectionEPSS 1.5%CVE-2024-57024MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiEPSS 1.5%CVE-2024-52010HIGHZoraxy has an authenticated command injection in the Web SSH featureEPSS 1.5%CVE-2026-5208HIGHImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in coolercontroldEPSS 1.5%CVE-2024-42503HIGHAuthenticated Remote Command Execution (RCE) Vulnerability in the Lua Package Within the AOS Command Line Interface (CLI)EPSS 1.5%CVE-2026-61409HIGHDell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements useEPSS 1.5%