Falhas do tipo CWE-78
4.653 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-8629MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8628MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2026-26191MEDIUMFleet vulnerable to OS command injection in software packagesEPSS 0.9%CVE-2024-28138HIGHOS Command InjectionEPSS 0.9%CVE-2025-12763MEDIUMCommand injection vulnerability allowing arbitrary command execution on WindowsEPSS 0.9%CVE-2025-7724HIGHUnauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2EPSS 0.9%CVE-2026-46394HIGHHAX CMS Vulnerable to Command Injection using Git.phpEPSS 0.9%CVE-2020-1609HIGHJunos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv6 packets and arbitrarily execute commands on the target device.EPSS 0.9%CVE-2026-75122HIGHPLANET GS-4210-16P2S V3 Command Injection via httpuploadcert.cgiEPSS 0.9%CVE-2026-14448HIGHAuthenticated RCE in system_certificates viewEPSS 0.9%CVE-2024-20424CRITICALA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower ManagemeEPSS 0.9%CVE-2023-25617CRITICALOS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)EPSS 0.9%CVE-2022-38387HIGHIBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on theEPSS 0.9%CVE-2026-6204HIGHLibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config EPSS 0.9%CVE-2023-3570HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2025-70831CRITICALA Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properEPSS 0.9%CVE-2023-24837HIGHHGiga PowerStation - Command InjectionEPSS 0.9%CVE-2023-53948CRITICALLilac-Reloaded for Nagios 2.0.8 Remote Code Execution via AutodiscoveryEPSS 0.9%CVE-2026-23855HIGHDell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, coEPSS 0.9%CVE-2026-33412MEDIUMVim affected by Command injection via newline in glob()EPSS 0.9%