Falhas do tipo CWE-78

4.591 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-34284CRITICALNagios XI < 2024R2 Authenticated Command Injection via WinRM PluginEPSS 4.1%CVE-2022-50596CRITICALD-Link DIR-1260 <= v1.20B05 GetDeviceSettings Unauthenticated Command InjectionEPSS 4.1%CVE-2021-27476CRITICALRockwell Automation FactoryTalk AssetCentre OS Command InjectionEPSS 4.1%CVE-2026-41925CRITICALWDR201A WiFi Extender OS Command Injection via adm.cgi (reboot_time)EPSS 4.1%CVE-2022-40189CRITICALApache Airlfow Pig Provider RCEEPSS 4.1%CVE-2019-14894HIGHA flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code executEPSS 4.1%CVE-2018-25126CRITICALTVT NVMS-9000 Hard-coded API Credentials & Command InjectionEPSS 4.1%CVE-2026-2157HIGHD-Link DIR-823X set_static_route_table sub_4175CC os command injectionEPSS 4.1%CVE-2026-2120HIGHD-Link DIR-823X Configuration Parameter set_server_settings os command injectionEPSS 4.1%CVE-2022-40220HIGHAn OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A speEPSS 4.1%CVE-2024-2812MEDIUMTenda AC15 WriteFacMac formWriteFacMac os command injectionEPSS 4.0%CVE-2025-11407MEDIUMD-Link DI-7001 MINI upgrade_filter.asp os command injectionEPSS 4.0%CVE-2021-33191—MiNiFi CPP arbitrary script execution is possible on the agent's host machine through the c2 protocolEPSS 4.0%CVE-2024-33896HIGHCosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parametEPSS 4.0%CVE-2024-2853MEDIUMTenda AC10U setsambacfg formSetSambaConf os command injectionEPSS 4.0%CVE-2024-2851MEDIUMTenda AC15 setsambacfg formSetSambaConf os command injectionEPSS 4.0%CVE-2026-61498CRITICALVitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.phpEPSS 4.0%CVE-2026-2084HIGHD-Link DIR-823X set_language os command injectionEPSS 4.0%CVE-2018-3785—A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.EPSS 4.0%CVE-2021-21018CRITICALMagnto Commerce Unauthorized Data Modification Could Lead To Arbitrary Code ExecutionEPSS 4.0%