Falhas do tipo CWE-78
4.591 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2022-33328CRITICALMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-craftEPSS 4.3%CVE-2022-33327CRITICALMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-craftEPSS 4.3%CVE-2026-3301CRITICALTotolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injectionEPSS 4.3%CVE-2022-33205CRITICALFour OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-EPSS 4.3%CVE-2022-33204CRITICALFour OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-EPSS 4.3%CVE-2022-33207CRITICALFour OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-EPSS 4.3%CVE-2022-33206CRITICALFour OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-EPSS 4.3%CVE-2026-23515CRITICALRCE - Command Injection in Signal K set-system-time pluginEPSS 4.3%CVE-2025-6896MEDIUMD-Link DI-7300G+ wget_test.asp os command injectionEPSS 4.3%CVE-2026-4170CRITICALTopsec TopACM HTTP Request nmc_sync.php os command injectionEPSS 4.3%CVE-2013-10058HIGHLinksys Routers apply.cgi Remote Command InjectionEPSS 4.3%CVE-2026-4480CRITICALSamba: samba: remote code execution in printing subsystem via unescaped job descriptionEPSS 4.3%CVE-2024-20399MEDIUMCisco NX-OS Software CLI Command Injection VulnerabilityEPSS 4.3%KEVCVE-2022-40222CRITICALAn OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A speciEPSS 4.3%CVE-2026-31975HIGHCloud CLI WebSocket shell injectionEPSS 4.3%CVE-2025-11491MEDIUMwonderwhy-er DesktopCommanderMCP command-manager.ts CommandManager os command injectionEPSS 4.3%CVE-2021-24684—PDF Light Viewer < 1.4.12 - Authenticated Command InjectionEPSS 4.3%CVE-2025-54405HIGHMultiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted sEPSS 4.3%CVE-2025-54406HIGHMultiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted sEPSS 4.3%CVE-2022-50789HIGHSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.phpEPSS 4.3%