Falhas do tipo CWE-78
4.654 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2022-26582HIGHPAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systoolEPSS 0.9%CVE-2025-44015LOWHybridDesk StationEPSS 0.9%CVE-2024-41790CRITICALA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitEPSS 0.9%CVE-2024-41788CRITICALA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitEPSS 0.9%CVE-2023-22304HIGHOS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker EPSS 0.9%CVE-2024-41789CRITICALA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitEPSS 0.9%CVE-2023-20219HIGHMultiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, rEPSS 0.9%CVE-2026-48345HIGHAnimate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 0.9%CVE-2026-4556HIGHmacOS Exam4 Local Privilege Escalation via Command InjectionEPSS 0.9%CVE-2024-10118CRITICALSECOM WRTR-304GN-304TW-UPSC - OS Command InjectionEPSS 0.9%CVE-2026-88888HIGHRenovate before 44.14.7 Command Injection via Mix organizationEPSS 0.9%CVE-2026-88885HIGHRenovate before 44.14.7 Command Injection via depNameEPSS 0.9%CVE-2026-73414CRITICALShescape: Shell injection via unescaped parentheses on Windows with CMDEPSS 0.9%CVE-2020-3167HIGHCisco FXOS and UCS Manager Software CLI Command Injection VulnerabilityEPSS 0.9%CVE-2026-12398HIGHGalaxy_ng: shell injection in legacy role import via unsanitized git ref namesEPSS 0.9%CVE-2026-28470CRITICALOpenClaw < 2026.2.2 - Exec Allowlist Bypass via Command Substitution in Double QuotesEPSS 0.9%CVE-2025-3626CRITICALOS Command Injection via Config Upload in WebUIEPSS 0.9%CVE-2023-28392HIGHWi-Fi AP UNIT AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_EPSS 0.9%CVE-2024-45798CRITICALMultiple Poisoned Pipeline Execution (PPE) vulnerabilitiesEPSS 0.9%CVE-2020-27298MEDIUMPhilips Interventional Workstations OS Command InjectionEPSS 0.9%