Falhas do tipo CWE-78
4.586 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-34102CRITICALCryptoLog Unauthenticated RCE via SQL Injection and Command InjectionEPSS 9.6%CVE-2023-6304HIGHTecno 4G Portable WiFi TR118 Ping Tool goform_get_cmd_process os command injectionEPSS 9.5%CVE-2025-6704CRITICALAn arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) caEPSS 9.5%CVE-2025-34322HIGHNagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language QueriesEPSS 9.5%CVE-2025-10328MEDIUMMiczFlor RPi-Jukebox-RFID playsinglefile.php os command injectionEPSS 9.4%CVE-2026-2847HIGHUTT HiPER 520 Web Management formReleaseConnect sub_44EFB4 os command injectionEPSS 9.4%CVE-2025-9387MEDIUMDCN DCME-720 Web Management Backend ip_block.php os command injectionEPSS 9.3%CVE-2022-36962HIGHSolarWinds Platform Command InjectionEPSS 9.3%CVE-2024-34921HIGHTOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.EPSS 9.2%CVE-2025-6485MEDIUMTOTOLINK A3002R formWlSiteSurvey os command injectionEPSS 9.1%CVE-2026-3040MEDIUMDrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injectionEPSS 9.1%CVE-2024-6185MEDIUMRuijie RG-UAC commit.php get_ip_addr_details os command injectionEPSS 9.1%CVE-2024-5337MEDIUMRuijie RG-UAC user_commit.php os command injectionEPSS 9.0%CVE-2024-5336MEDIUMRuijie RG-UAC vlan_add_commit.php addVlan os command injectionEPSS 9.0%CVE-2024-7580MEDIUMAlien Technology ALR-F800 system.html os command injectionEPSS 8.9%CVE-2018-14558CRITICALAn issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318EPSS 8.7%KEVCVE-2024-6186MEDIUMRuijie RG-UAC commit.php os command injectionEPSS 8.7%CVE-2023-34105HIGHSRS has command injection vulnerability in demonstration api-server for HTTP callback.EPSS 8.7%CVE-2024-10224MEDIUMQualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possiblyEPSS 8.6%CVE-2026-41179CRITICALRClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command executionEPSS 8.6%