Falhas do tipo CWE-78
4.591 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-0292MEDIUMTotolink LR1200GB cstecgi.cgi setOpModeCfg os command injectionEPSS 4.9%CVE-2018-11616—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115. User interactEPSS 4.9%CVE-2022-4221CRITICALOS command injection in ASUS M25 NASEPSS 4.9%CVE-2021-21016CRITICALMagento Commerce Unauthorized Data Modification Could Lead to Arbitrary Code ExecutionEPSS 4.9%CVE-2024-0293MEDIUMTotolink LR1200GB cstecgi.cgi setUploadSetting os command injectionEPSS 4.8%CVE-2025-7097CRITICALComodo Internet Security Premium Manifest File cis_update_x64.xml os command injectionEPSS 4.8%CVE-2026-78488MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper NeutraliEPSS 4.8%CVE-2025-9727MEDIUMD-Link DIR-816L soap.cgi soapcgi_main os command injectionEPSS 4.8%CVE-2022-45915HIGHILIAS before 7.16 allows OS Command Injection.EPSS 4.8%CVE-2023-0935MEDIUMDolphinPHP Incomplete Fix CVE-2021-46097 common.php os command injectionEPSS 4.8%CVE-2025-7382HIGHA command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achievEPSS 4.8%CVE-2023-2573HIGHAuthenticated Command InjectionEPSS 4.8%CVE-2023-2574HIGHAuthenticated Command InjectionEPSS 4.8%CVE-2025-50201CRITICALWeGIA OS Command Injection in debug_info.php parameter 'branch'EPSS 4.7%CVE-2026-15511CRITICALComfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injectionEPSS 4.7%CVE-2026-6516CRITICALRemote Code ExecutionEPSS 4.7%CVE-2026-79689MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper NeutraliEPSS 4.7%CVE-2026-2152HIGHD-Link DIR-615 Web Configuration adv_routing.php os command injectionEPSS 4.7%CVE-2021-40411CRITICALAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] thEPSS 4.7%CVE-2025-6899MEDIUMD-Link DI-7300G+/DI-8200G msp_info.htm os command injectionEPSS 4.7%