Falhas do tipo CWE-78

4.640 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-25828MEDIUMgrub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitizEPSS 1.4%CVE-2025-34150CRITICALShenzhen Aitemi M300 Wi-Fi Repeater PPPoE Username Command InjectionEPSS 1.4%CVE-2023-25925HIGHIBM Security Guardium Key Lifecycle Manager command injectionEPSS 1.4%CVE-2026-40711HIGHDell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contEPSS 1.3%CVE-2022-31486HIGHCommand injection via Advanced Networking route add functionalityEPSS 1.3%CVE-2026-21571CRITICALThis Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0,EPSS 1.3%CVE-2024-50359HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2025-28034CRITICALTOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000REPSS 1.3%CVE-2025-28035CRITICALTOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function tEPSS 1.3%CVE-2025-28036CRITICALTOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function EPSS 1.3%CVE-2024-12970LOWOS Command Injection in TUBITAK BILGEM's Pardus OS My ComputerEPSS 1.3%CVE-2023-40581HIGHyt-dlp command injection when using `%q` in `--exec` on WindowsEPSS 1.3%CVE-2026-65099HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A succEPSS 1.3%CVE-2026-65090HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A suEPSS 1.3%CVE-2024-42059HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmwaEPSS 1.3%CVE-2026-0273MEDIUMPAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UIEPSS 1.3%CVE-2026-65089HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injectioEPSS 1.3%CVE-2024-42060HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmwaEPSS 1.3%CVE-2022-35975CRITICALImproper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCodeEPSS 1.3%CVE-2026-65096HIGHNVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. EPSS 1.3%