Falhas do tipo CWE-78
4.652 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-57639MEDIUMOS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.userEPSS 1.0%CVE-2025-57457HIGHAn OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS CommandEPSS 1.0%CVE-2020-8105CRITICALCommand Execution due to unsanitized inputEPSS 1.0%CVE-2022-43758HIGHRancher: Command injection in Git packageEPSS 1.0%CVE-2023-1082HIGHWelotec: Command injection vulnerability in TK500v1 router seriesEPSS 1.0%CVE-2023-34108HIGHManipulation of Internal Dovecot Variables in mailcow via crafted PasswordsEPSS 1.0%CVE-2025-15388HIGHQNO Technology|VPN Firewall - OS Command InjectionEPSS 1.0%CVE-2023-35174HIGHLivebook Desktop's protocol handler can be exploited to execute arbitrary command on WindowsEPSS 1.0%CVE-2025-59370HIGHA command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentEPSS 1.0%CVE-2024-3104CRITICALRemote Code Execution in mintplex-labs/anything-llmEPSS 1.0%CVE-2026-34597HIGHCoolify: Authenticated Host RCEEPSS 1.0%CVE-2026-24719MEDIUMQTS, QuTS heroEPSS 1.0%CVE-2025-59156CRITICALCoolify has Docker Compose Injection issueEPSS 1.0%CVE-2021-42538HIGHEmerson WirelessHART GatewayEPSS 1.0%CVE-2025-14213HIGHCato's Socket WebUI is vulnerable to OS Command InjectionEPSS 1.0%CVE-2026-25622HIGHArista Edge Threat Management NGFW Captive Portal Custom Handler Command InjectionEPSS 1.0%CVE-2025-2071CRITICALOS Command Injection Vulnerability in FAST LTA Silent Brick WebUIEPSS 1.0%CVE-2026-25620HIGHArista Edge Threat Management NGFW Captive Portal Encrypted Password Command InjectionEPSS 1.0%CVE-2025-25220HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.EPSS 1.0%CVE-2026-25157HIGHOpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommandEPSS 1.0%