Falhas do tipo CWE-78
4.591 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-4499MEDIUMD-Link DIR-820LW SSDP ssdpcgi_main os command injectionEPSS 4.7%CVE-2013-10039HIGHGestioIP 3.0 ip_checkhost.cgi RCEEPSS 4.7%CVE-2023-6318CRITICALCommand injection in the processAnalyticsReport method from the com.webos.service.cloudupload serviceEPSS 4.7%CVE-2022-45639HIGHOS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m EPSS 4.7%CVE-2014-125118CRITICALeScan 5.5-2 Web Management Console Command InjectionEPSS 4.7%CVE-2026-33482HIGHAVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()EPSS 4.7%CVE-2026-1505HIGHD-Link DIR-615 URL Filter set_temp_nodes.php os command injectionEPSS 4.7%CVE-2018-1167—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User inEPSS 4.7%CVE-2026-74849CRITICALRemote code execution vulnerabilityEPSS 4.6%CVE-2024-2707MEDIUMTenda AC10U WriteFacMac formWriteFacMac os command injectionEPSS 4.6%CVE-2026-2151HIGHD-Link DIR-615 DMZ Host Feature adv_firewall.php os command injectionEPSS 4.6%CVE-2026-2063MEDIUMD-Link DIR-823X Web Management set_ac_server os command injectionEPSS 4.6%CVE-2025-54404HIGHMultiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted networEPSS 4.6%CVE-2025-54403HIGHMultiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted networEPSS 4.6%CVE-2026-8632HIGHHP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code ExecutionEPSS 4.6%CVE-2022-29472CRITICALAn OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One SEPSS 4.5%CVE-2026-34234CRITICALCtrlPanel: Unauthenticated RCE using installer scriptEPSS 4.5%CVE-2025-2717MEDIUMD-Link DIR-823X HTTP POST Request diag_nslookup sub_41710C os command injectionEPSS 4.5%CVE-2022-1986CRITICALOS Command Injection in gogs/gogsEPSS 4.5%CVE-2026-2143HIGHD-Link DIR-823X DDNS Service set_ddns os command injectionEPSS 4.5%