Falhas do tipo CWE-78
4.591 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-2129HIGHD-Link DIR-823X set_ac_status os command injectionEPSS 4.5%CVE-2025-34125CRITICALD-Link DSP-W110A1 Cookie Command InjectionEPSS 4.5%CVE-2021-30361—The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a commEPSS 4.5%CVE-2026-2061MEDIUMD-Link DIR-823X set_ipv6 sub_424D20 os command injectionEPSS 4.5%CVE-2024-3880MEDIUMTenda W30E WriteFacMac formWriteFacMac os command injectionEPSS 4.4%CVE-2025-34101CRITICALServiio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO ParameterEPSS 4.4%CVE-2026-58479CRITICALSustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command InjectionEPSS 4.4%CVE-2024-8234HIGH** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in theEPSS 4.4%CVE-2020-5758—Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attaEPSS 4.4%CVE-2026-7119HIGHTenda HG3 formCountrystr os command injectionEPSS 4.4%CVE-2026-7096HIGHTenda HG3 formgponConf os command injectionEPSS 4.4%CVE-2024-11046MEDIUMD-Link DI-8003 upgrade_filter.asp upgrade_filter_asp os command injectionEPSS 4.4%CVE-2025-34319CRITICALTOTOLINK N300RT <= V2.1.8-B20201030.1539 Boa formWsc RCEEPSS 4.4%CVE-2026-56415CRITICALOS Command Injection in StoneFly Storage ConcentratorEPSS 4.4%CVE-2022-33312CRITICALMultiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-craEPSS 4.3%CVE-2022-33325CRITICALMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-craftEPSS 4.3%CVE-2022-33314CRITICALMultiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-craEPSS 4.3%CVE-2022-33327CRITICALMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-craftEPSS 4.3%CVE-2022-33329CRITICALMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-craftEPSS 4.3%CVE-2022-33326CRITICALMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-craftEPSS 4.3%