Falhas do tipo CWE-78
4.644 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2023-22815MEDIUMPost-authentication remote command injection vulnerability on Western Digital My Cloud OS 5 devicesEPSS 1.3%CVE-2023-25313CRITICALOS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the viEPSS 1.3%CVE-2026-41315CRITICALmdserver-web: Missing Authorization and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.3%CVE-2024-50393HIGHQTS, QuTS heroEPSS 1.3%CVE-2026-45629CRITICALDokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket EndpointEPSS 1.3%CVE-2026-0786HIGHALGO 8180 IP Audio Alerter SCI Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-5416HIGHCommand Injection via name parameterEPSS 1.3%CVE-2023-24816MEDIUMset_term_title command injection in ipythonEPSS 1.3%CVE-2026-59111CRITICALCommand Injection vulnerability in eObčanka-IdentifikaceEPSS 1.3%CVE-2025-64111CRITICALGogs's update .git/config file allows remote command executionEPSS 1.3%CVE-2011-3178HIGHopenbuildservice webui code injectionEPSS 1.3%CVE-2025-37170HIGHAuthenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceEPSS 1.3%CVE-2023-35019HIGHIBM Security Verify Governance command executionEPSS 1.3%CVE-2025-56124HIGHOS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands viaEPSS 1.3%CVE-2024-42757CRITICALCommand injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat functionEPSS 1.3%CVE-2025-50946MEDIUMOS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.EPSS 1.3%CVE-2025-11005CRITICALTOTOLINK X6000R Unauthenticated Command Injection VulnerabilityEPSS 1.3%CVE-2026-62312HIGH9Router: Authenticated RCE via Unvalidated MCP Plugin ArgumentsEPSS 1.3%CVE-2026-44590CRITICALSherlock: Command Injection via pull_request_target in validate_modified_targets.ymlEPSS 1.3%CVE-2022-24390HIGHAuthenticated Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.3%