Falhas do tipo CWE-78
4.645 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2022-34883HIGHOS Command Injection Vulnerability in RAID Manager Storage Replication AdapterEPSS 1.3%CVE-2022-47616HIGHHitron Technologies Inc. CODA-5310 - Remote Command ExecutionEPSS 1.3%CVE-2025-20014CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.3%CVE-2025-20061CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.3%CVE-2024-50371CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2025-24382HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 1.3%CVE-2024-50372CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2024-50373CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2026-28279HIGH`osctrl-admin` Vulnerable to OS Command Injection via Environment ConfigurationEPSS 1.3%CVE-2023-40480HIGHNETGEAR RAX30 DHCP Server Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-40479HIGHNETGEAR RAX30 UPnP Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2025-37172HIGHAuthenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceEPSS 1.3%CVE-2023-49329HIGHAnomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This aEPSS 1.3%CVE-2024-28048CRITICALOS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS cEPSS 1.3%CVE-2022-44201CRITICALD-Link DIR823G 1.02B05 is vulnerable to Commad Injection.EPSS 1.3%CVE-2026-26318HIGHsysteminformation has Command Injection via Unsanitized `locate` Output in `versions()`EPSS 1.3%CVE-2018-25118CRITICALGeoVision Command Injection RCE via /PictureCatch.cgiEPSS 1.3%CVE-2021-34362HIGHCommand Injection Vulnerability in Media Streaming Add-onEPSS 1.3%CVE-2026-35018HIGHNetComm NF20MESH < R6B032 Authenticated RCE via OS Command InjectionEPSS 1.3%CVE-2026-49959HIGHHermes WebUI < 0.51.311 RCE via Git Configuration InjectionEPSS 1.3%