Falhas do tipo CWE-78
4.645 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2023-3260HIGHThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parametEPSS 1.3%CVE-2025-54763HIGHFutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the EPSS 1.3%CVE-2025-53508HIGHMultiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executEPSS 1.3%CVE-2023-35722HIGHNETGEAR RAX30 UPnP Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-26039HIGHZoneMinder vulnerable to OS Command injection in daemonControl() APIEPSS 1.3%CVE-2024-22423HIGHyt-dlp `--exec` command injection when using `%q` in yt-dlp on WindowsEPSS 1.3%CVE-2025-66576HIGHRemote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)EPSS 1.3%CVE-2023-4033HIGHOS Command Injection in mlflow/mlflowEPSS 1.3%CVE-2025-65199HIGHWindscribe for Linux 'changeMTU' local privilege escalationEPSS 1.3%CVE-2022-45045HIGHMultiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.0000EPSS 1.3%CVE-2026-84830HIGHOS command injection in privileged configuration handlingEPSS 1.2%CVE-2024-47901CRITICALA vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All veEPSS 1.2%CVE-2026-23678HIGHBinardat 10G08-0800GSM Network Switch Traceroute CLI Command InjectionEPSS 1.2%CVE-2019-16790MEDIUMRemote Code Execution in Tiny File ManagerEPSS 1.2%CVE-2023-3573HIGHPHOENIX CONTACT: Command Injection in WP 6xxx Web panelsEPSS 1.2%CVE-2026-18264HIGHNoMachine getstat Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-0740CRITICALEclipse Target Management <= 4.5.500 Command InjectionEPSS 1.2%CVE-2023-3974CRITICALOS Command Injection in jgraph/drawioEPSS 1.2%CVE-2025-46272CRITICALPlanet Technology Network Products OS Command InjectionEPSS 1.2%CVE-2025-64444HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. EPSS 1.2%