Falhas do tipo CWE-78
4.664 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-60959HIGHOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 0.7%CVE-2026-73483CRITICALFlowise before 3.1.3 Sandbox Escape via PuppeteerEPSS 0.7%CVE-2024-43386HIGHPhoenix Contact: OS command execution through EMAIL_NOTIFICATION.TO in mGuard devices.EPSS 0.7%CVE-2025-60962HIGHOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 0.7%CVE-2024-2415HIGHCommand injection vulnerability in Movistar 4G routerEPSS 0.7%CVE-2026-82077HIGHPaperCut NG/MF: Remote Code Execution via Scan2FaxEPSS 0.7%CVE-2025-41683HIGHWeidmueller: Root Command Injection via Unsanitized Input in event_mail_test EndpointEPSS 0.7%CVE-2025-41684HIGHWeidmueller: Root Command Injection via Unsanitized Input in tls_iotgen_setting EndpointEPSS 0.7%CVE-2026-32034MEDIUMOpenClaw < 2026.2.21 - Insecure Control UI Authentication over Plaintext HTTPEPSS 0.7%CVE-2025-64340MEDIUMFastMCP has a Command Injection vulnerability - Gemini CLIEPSS 0.7%CVE-2024-0401HIGHASUS OVPN RCEEPSS 0.7%CVE-2025-6193MEDIUMTrustyai-explainability: command injection via lmevaljob crEPSS 0.7%CVE-2022-48601HIGHA SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inEPSS 0.7%CVE-2022-48602HIGHA SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inEPSS 0.7%CVE-2023-32622—Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privEPSS 0.7%CVE-2022-48603HIGHA SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 0.7%CVE-2022-48604HIGHA SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input anEPSS 0.7%CVE-2022-48591HIGHA SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes uEPSS 0.7%CVE-2022-48592HIGHA SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takesEPSS 0.7%CVE-2022-48598HIGHA SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controllEPSS 0.7%