Falhas do tipo CWE-78
4.578 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-5445MEDIUMLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 RP_checkFWByBBS os command injectionEPSS 14.9%CVE-2023-5494MEDIUMByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform download.php os command injectionEPSS 14.8%CVE-2022-43548HIGHA OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost cEPSS 14.6%CVE-2024-13985CRITICALDahua EIMS capture_handle.action RCEEPSS 14.6%CVE-2024-3799HIGHShell command injection in PhonieboxEPSS 14.6%CVE-2022-20650HIGHCisco NX-OS Software NX-API Command Injection VulnerabilityEPSS 14.5%CVE-2023-23369CRITICALQTS, Multimedia Console, and Media Streaming add-onEPSS 14.5%CVE-2025-6898MEDIUMD-Link DI-7300G+ in proxy_client.asp os command injectionEPSS 14.5%CVE-2026-4480CRITICALSamba: samba: remote code execution in printing subsystem via unescaped job descriptionEPSS 13.9%CVE-2025-15471CRITICALTRENDnet TEW-713RE formFSrvX os command injectionEPSS 13.8%CVE-2024-12686MEDIUMCommand Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)EPSS 13.8%KEVCVE-2025-34311HIGHIPFire < v2.29 Command Injection via Proxy Report CreationEPSS 13.8%CVE-2025-5573MEDIUMD-Link DCS-932L setSystemWizard setSystemControl os command injectionEPSS 13.8%CVE-2023-47415HIGHCypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.EPSS 13.8%CVE-2025-2605CRITICALAuthenticated command injectionEPSS 13.7%CVE-2026-22844CRITICALZoom Node Deployments - Command InjectionEPSS 13.6%CVE-2013-10050HIGHD-Link Devices tools_vct.xgi Authenticated RCEEPSS 13.6%CVE-2026-10727HIGHAn OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker EPSS 13.6%CVE-2025-5571MEDIUMD-Link DCS-932L setSystemAdmin os command injectionEPSS 13.6%CVE-2013-10037CRITICALWebTester 5.x install2.php Unauthenticated Command ExecutionEPSS 13.6%