Falhas do tipo CWE-78
4.645 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2023-41289MEDIUMQcalAgentEPSS 1.1%CVE-2023-31209HIGHCommand injection via active checks and REST APIEPSS 1.1%CVE-2024-11983HIGHBillion Electric router - OS Command InjectionEPSS 1.1%CVE-2023-47560HIGHQuMagieEPSS 1.1%CVE-2024-46316HIGHDrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cEPSS 1.1%CVE-2026-48163HIGHMariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)EPSS 1.1%CVE-2020-36198MEDIUMCommand Injection Vulnerability in Malware RemoverEPSS 1.1%CVE-2023-39294MEDIUMQTS, QuTS heroEPSS 1.1%CVE-2025-26856HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE aEPSS 1.1%CVE-2023-53872CRITICALWp2Fac 1.0 OS Command Injection via send.php EndpointEPSS 1.1%CVE-2025-57636MEDIUMOS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability viaEPSS 1.1%CVE-2025-58116HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and WN-7D36QR/UE. If thEPSS 1.1%CVE-2024-48890MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP conneEPSS 1.1%CVE-2026-31246MEDIUMGPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (CWE-78) in the ExecuEPSS 1.1%CVE-2024-0164HIGH
Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker couEPSS 1.1%CVE-2021-27252HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1EPSS 1.1%CVE-2026-16445HIGHDracut: dracut: root code execution via dhcp options command injection in networkmanager initrd moduleEPSS 1.1%CVE-2023-4149CRITICALWAGO: OS Command Injection Vulnerability in Managed SwitchEPSS 1.1%CVE-2024-39685CRITICALfishaudio/Bert-VITS2 Command Injection in webui_preprocess.py resample functionEPSS 1.1%CVE-2025-10265HIGHDigiever|NVR - OS Command InjectionEPSS 1.1%