Falhas do tipo CWE-78
4.652 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-23961MEDIUMAlpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution VulnerabilityEPSS 1.0%CVE-2025-67447CRITICALThe network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The applicatiEPSS 1.0%CVE-2026-94367HIGHOpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated aEPSS 1.0%CVE-2026-31019HIGHIn the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functEPSS 1.0%CVE-2018-20106MEDIUMSMB printer settings don't escape characters in passwords properlyEPSS 1.0%CVE-2026-18284HIGHSony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation VulnerabilityEPSS 1.0%CVE-2010-20059CRITICALFreeNAS < 0.7.2 rev 5543 exec_raw.php Arbitrary Command ExecutionEPSS 1.0%CVE-2026-7551HIGHHKUDS OpenHarness Remote Command Execution via /bridge Slash CommandEPSS 1.0%CVE-2021-47794HIGHZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated)EPSS 1.0%CVE-2024-52723CRITICALIn TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacEPSS 1.0%CVE-2020-3377MEDIUMCisco Data Center Network Manager Command Injection VulnerabilityEPSS 1.0%CVE-2024-28033HIGHOS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitEPSS 1.0%CVE-2024-50375CRITICALA CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AEPSS 1.0%CVE-2024-13089HIGHAuthenticated RCE in update functionality in Guardian/CMC before 24.6.0EPSS 1.0%CVE-2025-24306HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.EPSS 1.0%CVE-2024-38508HIGHA privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an aEPSS 1.0%CVE-2026-35867LOWA Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2EPSS 1.0%CVE-2024-1880HIGHOS Command Injection in MacOS Text-To-Speech Class in significant-gravitas/autogptEPSS 1.0%CVE-2026-33046HIGHIndico discloses local files resulting in Remote Code Execution through LaTeX injectionEPSS 1.0%CVE-2026-14522HIGHIBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settingsEPSS 1.0%