Falhas do tipo CWE-78
4.602 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2021-21888CRITICALAn OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4EPSS 3.9%CVE-2021-3584—A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration opEPSS 3.9%CVE-2018-19007—In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable tEPSS 3.9%CVE-2016-15047HIGHAVTECH CloudSetup.cgi Authenticated Command InjectionEPSS 3.9%CVE-2025-66209CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database BackupEPSS 3.9%CVE-2017-17407—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.EPSS 3.9%CVE-2026-28409CRITICALWeGIA Vulnerable to Remote Code Execution (RCE) via OS Command InjectionEPSS 3.8%CVE-2026-4840HIGHNetcore Power 15AX Diagnostic Tool netis.cgi setTools os command injectionEPSS 3.8%CVE-2021-31891—A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on DebEPSS 3.8%CVE-2022-44808CRITICALA command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to executeEPSS 3.8%CVE-2023-38120HIGHAdtran SR400ac ping Command Injection Remote Code Execution VulnerabilityEPSS 3.8%CVE-2024-0299HIGHTotolink N200RE cstecgi.cgi setTracerouteCfg os command injectionEPSS 3.8%CVE-2024-0294HIGHTotolink LR1200GB cstecgi.cgi setUssd os command injectionEPSS 3.8%CVE-2024-0296HIGHTotolink N200RE cstecgi.cgi NTPSyncWithHost os command injectionEPSS 3.8%CVE-2024-0298HIGHTotolink N200RE cstecgi.cgi setDiagnosisCfg os command injectionEPSS 3.8%CVE-2024-0295HIGHTotolink LR1200GB cstecgi.cgi setWanCfg os command injectionEPSS 3.8%CVE-2024-0297HIGHTotolink N200RE cstecgi.cgi UploadFirmwareFile os command injectionEPSS 3.8%CVE-2020-26301HIGHCommand injection in mscdex/ssh2EPSS 3.8%CVE-2025-34044CRITICALWIFISKY 7-Layer Flow Control Router Remote Command ExecutionEPSS 3.8%CVE-2026-18900HIGHH3C NX15 Backend RPC esps file.exec os command injectionEPSS 3.8%