Falhas do tipo CWE-78
4.668 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-56686HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InEPSS 0.6%CVE-2025-22367HIGHMennekes smart/premium charges systems, Command injection in time settingEPSS 0.6%CVE-2025-25039MEDIUMAuthenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.6%CVE-2026-59910HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InEPSS 0.6%CVE-2025-41663CRITICALWeidmueller: Security routers IE-SR-2TX are affected by Command InjectionEPSS 0.6%CVE-2024-22228HIGH
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attackerEPSS 0.6%CVE-2024-24431HIGHA reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a craftedEPSS 0.6%CVE-2023-49691HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.6%CVE-2024-22227HIGH
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could poEPSS 0.6%CVE-2026-67324CRITICALGitPython 3.1.50 Authentication Bypass via Joined Short OptionsEPSS 0.6%CVE-2025-65882CRITICALAn issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function creaEPSS 0.6%CVE-2025-37126HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line InterfaceEPSS 0.6%CVE-2025-52573MEDIUMCommand Injection in MCP Server ios-simulator-mcpEPSS 0.6%CVE-2026-73662HIGHAuthenticated FreePBX Music RCE via mpg123 and Asterisk Call FilesEPSS 0.6%CVE-2025-53542HIGHKubernetes Headlamp Allows Arbitrary Command Injection in macOS Process headlamp@codeSignEPSS 0.6%CVE-2025-12744HIGHAbrt: command-injection in abrt leading to local privilege escalationEPSS 0.6%CVE-2022-48684HIGHAn issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templatEPSS 0.6%CVE-2026-73716HIGHUnauthenticated Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.6%CVE-2026-3821HIGHSupermicro SMASH service contain an Arbitrary code execution issueEPSS 0.6%CVE-2026-52484HIGHAn issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/deEPSS 0.6%