Falhas do tipo CWE-78
4.645 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-54082HIGHhome 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS cEPSS 1.2%CVE-2024-34210HIGHTOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate funEPSS 1.2%CVE-2024-53700MEDIUMQHoraEPSS 1.2%CVE-2026-87969HIGHWatchGuard AP Authenticated Command Injection in Diagnostic CLIEPSS 1.2%CVE-2025-56413HIGHOS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operationEPSS 1.2%CVE-2026-84837HIGHRpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball pathEPSS 1.2%CVE-2026-8660HIGHOS Command Injection in Rapid7 InsightConnect Ping PluginEPSS 1.2%CVE-2026-8592HIGHOS Command Injection in Rapid7 InsightConnect AWK PluginEPSS 1.2%CVE-2026-80138CRITICALClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath ParameterEPSS 1.2%CVE-2026-8665HIGHOS Command Injection in Rapid7 InsightConnect Translate PluginEPSS 1.2%CVE-2026-8666HIGHOS Command Injection in Rapid7 InsightConnect Traceroute PluginEPSS 1.2%CVE-2026-19978MEDIUMjiantao88 android-mcp-server Command Execution index.js child_process.exec os command injectionEPSS 1.2%CVE-2026-0855HIGHMerit LILIN|IP Camera - OS Command InjectionEPSS 1.2%CVE-2026-24506HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 1.2%CVE-2023-47220MEDIUMMedia Streaming add-onEPSS 1.2%CVE-2026-4802HIGHCockpit: cockpit: arbitrary command execution via crafted links in system logs uiEPSS 1.2%CVE-2023-26128HIGHAll versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sanEPSS 1.2%CVE-2012-10037CRITICALPhpTax pfilez Parameter Exec Remote Code InjectionEPSS 1.2%CVE-2023-50198HIGHD-Link G416 cfgsave Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2026-40030HIGHparseusbs < 1.9 Command Injection via Volume Path ArgumentEPSS 1.2%