Falhas do tipo CWE-78

4.602 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-1544MEDIUMD-Link DIR-823X set_mode sub_41E2A0 os command injectionEPSS 3.8%CVE-2025-34024CRITICALEdimax EW-7438RPn Mini OS Command Injection via mp.aspEPSS 3.8%CVE-2020-15123CRITICALCommand injection in codecov (npm package)EPSS 3.8%CVE-2026-25643CRITICALFrigate Affected by Authenticated Remote Command Execution (RCE) and Container EscapeEPSS 3.8%CVE-2019-1885HIGHCisco Integrated Management Controller Command Injection VulnerabilityEPSS 3.8%CVE-2025-7553MEDIUMD-Link DIR-818LW System Time Page os command injectionEPSS 3.8%CVE-2021-30166HIGHMERIT LILIN ENT.CO.,LTD. P2/Z2/P3/Z3 IP camera - Command InjectionEPSS 3.8%CVE-2025-11141MEDIUMRuijie NBR2100G-E branch_passw.php listAction os command injectionEPSS 3.8%CVE-2022-50791HIGHSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.phpEPSS 3.8%CVE-2022-31249HIGH[RANCHER] OS command injection in Rancher and FleetEPSS 3.8%CVE-2022-22140CRITICALAn os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specEPSS 3.7%CVE-2022-21178CRITICALAn os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A sEPSS 3.7%CVE-2024-2910MEDIUMRuijie RG-EG350 HTTP POST Request vpnAction os command injectionEPSS 3.7%CVE-2023-48842CRITICALD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.EPSS 3.7%CVE-2023-4410MEDIUMTOTOLINK EX1200L setDiagnosisCfg os command injectionEPSS 3.7%CVE-2023-4412MEDIUMTOTOLINK EX1200L setWanCfg os command injectionEPSS 3.7%CVE-2022-24796CRITICALRemote Command Injection in RaspberryMaticEPSS 3.7%CVE-2026-86299CRITICALLinksys RE7000 PingTest json.cgi platform_event_pingTest os command injectionEPSS 3.7%CVE-2018-4859—A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the web interface (443/EPSS 3.7%CVE-2018-4860—A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the web interface (443/EPSS 3.7%