Falhas do tipo CWE-78
4.627 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-37626HIGHA command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the ifaceEPSS 1.5%CVE-2023-25607HIGHAn improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 EPSS 1.5%CVE-2024-27521HIGHTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multipEPSS 1.5%CVE-2023-23367MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.5%CVE-2022-41955HIGHAutolab is vulnerable to remote code execution (RCE) via MOSS functionalityEPSS 1.5%CVE-2023-32350HIGH
Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in aEPSS 1.5%CVE-2026-24252HIGHNVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability EPSS 1.5%CVE-2026-16488LOWQUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injectionEPSS 1.5%CVE-2022-37878HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.5%CVE-2026-59681HIGHyast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD joinEPSS 1.5%CVE-2023-3741—An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on theEPSS 1.5%CVE-2026-49481CRITICALUpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmdEPSS 1.5%CVE-2025-2733MEDIUMmannaandpoem OpenManus Prompt python_execute.py os command injectionEPSS 1.5%CVE-2024-43656CRITICALA backup can be manipulated and then restored to create arbitrary files inside the <redacted> directory. A CGI script can be added to the web directory this way, allowing for full remote code execution.EPSS 1.5%CVE-2023-28983HIGHJunos OS Evolved: Shell Injection vulnerability in the gNOI serverEPSS 1.5%CVE-2023-35959HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35964HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35960HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35961HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35963HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%