Falhas do tipo CWE-78

4.599 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-34082CRITICALIGEL OS Secure Terminal and Secure Shadow Remote Code ExecutionEPSS 6.7%CVE-2024-4504MEDIUMRuijie RG-UAC commit.php os command injectionEPSS 6.7%CVE-2025-65202HIGHTRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP EPSS 6.7%CVE-2017-10955HIGHThis vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. AutheEPSS 6.7%CVE-2020-37125CRITICALEdimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code ExecutionEPSS 6.7%CVE-2026-41922CRITICALWDR201A WiFi Extender OS Command Injection via wireless.cgiEPSS 6.7%CVE-2026-2188HIGHUTT 进取 521G formPdbUpConfig sub_446B18 os command injectionEPSS 6.7%CVE-2019-5142HIGHAn exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A speciallyEPSS 6.6%CVE-2026-3101MEDIUMIntelbras TIP 635G Ping os command injectionEPSS 6.6%CVE-2025-54382CRITICALCherry Studio RCE Vulnerability DisclosureEPSS 6.6%CVE-2025-8818MEDIUMLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setLan setDFSSetting os command injectionEPSS 6.5%CVE-2019-25065MEDIUMOpenNetAdmin os command injectionEPSS 6.5%CVE-2013-10060CRITICALNetgear Routers pppoe.cgi RCEEPSS 6.5%CVE-2026-8264MEDIUMTenda AC6 httpd WifiApScan formWifiApScan os command injectionEPSS 6.5%CVE-2024-33112HIGHD-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.EPSS 6.5%CVE-2024-28892CRITICALAn OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary cEPSS 6.5%CVE-2017-14001—An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS commEPSS 6.4%CVE-2023-6319CRITICALCommand injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager serviceEPSS 6.4%CVE-2026-3485CRITICALD-Link DIR-868L SSDP Service sub_1BF84 os command injectionEPSS 6.4%CVE-2024-4813MEDIUMRuijie RG-UAC interface_commit.php os command injectionEPSS 6.4%