Falhas do tipo CWE-78
4.653 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-48554HIGHNagios Core / XI Authenticated RCE via Unfiltered NOTIFICATION-Family Macro SubstitutionEPSS 1.0%CVE-2025-27804MEDIUMOS Command Injection Vulnerability in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 1.0%CVE-2023-47563HIGHVideo StationEPSS 1.0%CVE-2026-16469HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 1.0%CVE-2024-51010HIGHNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerabEPSS 1.0%CVE-2024-51009HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulneraEPSS 1.0%CVE-2024-50993HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. ThiEPSS 1.0%CVE-2021-27256HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1EPSS 1.0%CVE-2024-51008HIGHNetgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerEPSS 1.0%CVE-2023-49900CRITICALOrigin Validation Error in X-Rite MA-T6EPSS 1.0%CVE-2023-46306HIGHThe web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command coEPSS 1.0%CVE-2021-21569MEDIUMDell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clienEPSS 1.0%CVE-2025-25895HIGHAn OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulnerability allows attacEPSS 1.0%CVE-2025-25893HIGHAn OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocolEPSS 1.0%CVE-2026-76228HIGHRenovate before 42.68.5 Remote Code Execution via Gradle WrapperEPSS 1.0%CVE-2025-25894HIGHAn OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters. This vulnerability EPSS 1.0%CVE-2023-34116HIGHImproper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalatioEPSS 1.0%CVE-2023-6357HIGHOS Command Injection in multiple CODESYS productsEPSS 1.0%CVE-2023-20013MEDIUMMultiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary coEPSS 1.0%CVE-2023-20017MEDIUMMultiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary coEPSS 1.0%