Falhas do tipo CWE-78
4.664 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-100844HIGHMONAI before 1.6.0 OS Command Injection via dataset_name_or_idEPSS 0.8%CVE-2023-43068HIGH
Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted shell in SSH. An authEPSS 0.8%CVE-2026-4946HIGHNSA Ghidra Auto-Analysis Annotation Command ExecutionEPSS 0.8%CVE-2024-28748HIGHifm: Reading function in Smart PLC allows command injections EPSS 0.8%CVE-2024-28750HIGHifm: Deleting function in Smart PLC allows command injectionsEPSS 0.8%CVE-2026-47751MEDIUMClaude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret ExfiltrationEPSS 0.8%CVE-2024-28749HIGHifm: Writing file function in Smart PLC allows command injections EPSS 0.8%CVE-2024-7699HIGHPhoenix Contact: OS command execution in MGUARD productsEPSS 0.8%CVE-2026-54088CRITICALFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)EPSS 0.8%CVE-2023-34213HIGHSecond Order Command-injection Vulnerability in the Key-generation FunctionEPSS 0.8%CVE-2026-75600HIGHFreePBX: Authenticated API generatedocs Host Command InjectionEPSS 0.8%CVE-2025-8654HIGHKenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution VulnerabilityEPSS 0.8%CVE-2022-39057HIGHChanging Information Technology Inc. RAVA certificate validation system - Command InjectionEPSS 0.8%CVE-2024-48861HIGHQHoraEPSS 0.8%CVE-2022-24441MEDIUMCode InjectionEPSS 0.8%CVE-2023-34139HIGHA command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 PatEPSS 0.8%CVE-2025-31692HIGHAI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021EPSS 0.8%CVE-2026-12943CRITICALThis Power Hardware Management Console update is being released to addressEPSS 0.8%CVE-2023-42128HIGHMagnet Forensics AXIOM Command Injection Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-35906CRITICALAn undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute aEPSS 0.8%