Falhas do tipo CWE-78

4.645 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2021-47851CRITICALMini Mouse 9.2.0 - Remote Code ExecutionEPSS 1.2%CVE-2023-39300HIGHQTSEPSS 1.2%CVE-2024-25626HIGHYocto Project Security Advisory - BitBake/ToasterEPSS 1.2%CVE-2025-60965CRITICALOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 1.2%CVE-2025-60964CRITICALOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 1.2%CVE-2025-20294MEDIUMCisco UCS Manager Software Command Injection VulnerabilityEPSS 1.2%CVE-2026-47294HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 1.2%CVE-2020-37032HIGHWing FTP Server 6.3.8 - Remote Code ExecutionEPSS 1.2%CVE-2024-32850CRITICALImproper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 EPSS 1.2%CVE-2023-3454HIGHRemote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary codEPSS 1.2%CVE-2025-10659CRITICALMegaSys Enterprises Telenium Online Web Application OS Command InjectionEPSS 1.2%CVE-2025-41385HIGHAn OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed byEPSS 1.2%CVE-2025-28038CRITICALTOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx functioEPSS 1.2%CVE-2025-28037CRITICALTOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerabEPSS 1.2%CVE-2025-28039CRITICALTOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW functionEPSS 1.2%CVE-2025-59377LOWfeiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is usEPSS 1.2%CVE-2026-21719HIGHAn OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute EPSS 1.2%CVE-2024-53256HIGHRizin has a command injection via RzBinInfo bclass due legacy codeEPSS 1.2%CVE-2024-45721HIGHhome 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration scEPSS 1.2%CVE-2023-41346HIGHASUS RT-AX55 - command injection - 2EPSS 1.2%