Falhas do tipo CWE-78
4.653 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-25157HIGHOpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommandEPSS 1.0%CVE-2024-54181HIGHIBM WebSphere Automation command injectionEPSS 1.0%CVE-2025-25220HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.EPSS 1.0%CVE-2022-45026CRITICALAn issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM eEPSS 1.0%CVE-2022-42053HIGHTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parEPSS 1.0%CVE-2023-22280HIGHMAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancEPSS 1.0%CVE-2021-35402CRITICALPROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip EPSS 1.0%CVE-2025-25053HIGHOS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitraryEPSS 1.0%CVE-2025-28256CRITICALAn issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /liEPSS 1.0%CVE-2021-3769HIGHOS Command Injection in ohmyzsh/ohmyzshEPSS 1.0%CVE-2022-1359MEDIUMCambium Networks cnMaestro Path TraversalEPSS 1.0%CVE-2026-44168HIGHMariaDB: wsrep SST unsafe parameter handling on the donor sideEPSS 1.0%CVE-2026-27565CRITICALRemote code execution via uploading a malicious IODD fileEPSS 1.0%CVE-2023-41283MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-41282MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-41281MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-44304HIGH
Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges could potentially exploEPSS 1.0%CVE-2020-7804MEDIUMActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShelEPSS 1.0%CVE-2025-41427HIGHWRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command InjectEPSS 1.0%CVE-2026-48553HIGHNagios Core / XI Authenticated RCE via Custom-Variable Macro InjectionEPSS 1.0%