Falhas do tipo CWE-78
4.652 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-21833HIGHMultiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. TheEPSS 1.1%CVE-2024-46484CRITICALTRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.EPSS 1.1%CVE-2026-22897HIGHQuNetSwitchEPSS 1.1%CVE-2024-11253HIGHA post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmEPSS 1.1%CVE-2023-32548HIGHOS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attackEPSS 1.1%CVE-2024-12009HIGHA post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and eEPSS 1.1%CVE-2024-12010HIGHA post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.EPSS 1.1%CVE-2022-48624HIGHclose_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.EPSS 1.1%CVE-2026-73769HIGHAuthenticated Remote Code Execution in CPPM Web InterfaceEPSS 1.1%CVE-2025-43978HIGHJointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /EPSS 1.1%CVE-2026-76690HIGHAuthenticated Remote Code Execution Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 1.1%CVE-2025-69262HIGHpnpm vulnerable to Command Injection via environment variable substitutionEPSS 1.1%CVE-2025-55589MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and cEPSS 1.1%CVE-2022-25906HIGHAll versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes beEPSS 1.1%CVE-2026-39862MEDIUMTophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat LinkEPSS 1.1%CVE-2024-2243HIGHCsmock: command injection vulnerability in csmock-plugin-snykEPSS 1.1%CVE-2026-32191CRITICALMicrosoft Bing Images Remote Code Execution VulnerabilityEPSS 1.1%CVE-2025-22469MEDIUMOS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. AnEPSS 1.1%CVE-2025-1753HIGHCommand Injection in LLama-Index CLI in run-llama/llama_indexEPSS 1.1%CVE-2022-41871MEDIUMSEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in thEPSS 1.1%