Falhas do tipo CWE-78
4.602 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-15254MEDIUMTenda W6-S ATE Service ate TendaAte os command injectionEPSS 3.7%CVE-2022-27804HIGHAn os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, Inc. iota All-In-One SEPSS 3.7%CVE-2025-34151CRITICALShenzhen Aitemi M300 Wi-Fi Repeater PPPoE Password Command InjectionEPSS 3.7%CVE-2022-33140—Improper Neutralization of Command Elements in Shell User Group ProviderEPSS 3.7%CVE-2026-76978HIGHCommand Injection vulnerabilityEPSS 3.7%CVE-2021-1264CRITICALCisco DNA Center Command Runner Command Injection VulnerabilityEPSS 3.7%CVE-2026-26068CRITICALemp3r0r Agent-Controlled Metadata to Operator RCE (tmux Command Injection)EPSS 3.7%CVE-2023-24595HIGHAn OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A speciallyEPSS 3.7%CVE-2026-19771HIGHBaicells EG3661M LuCI Web luci os command injectionEPSS 3.7%CVE-2023-24805HIGHCommand injection in cups-filtersEPSS 3.7%CVE-2024-5421HIGHAuthenticated Command InjectionEPSS 3.7%CVE-2022-1440CRITICALCommand Injection vulnerability in git-interface@2.1.1 in yarkeev/git-interfaceEPSS 3.7%CVE-2025-67840HIGHMultiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_EPSS 3.7%CVE-2026-17176HIGHOS command injection Vulnerability in Deco BE11000EPSS 3.7%CVE-2026-42589CRITICALGotenberg: Unauthenticated RCE via ExifTool Metadata Key InjectionEPSS 3.7%CVE-2024-8926HIGHPHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)EPSS 3.7%CVE-2022-50794CRITICALSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via UsernameEPSS 3.7%CVE-2021-40409CRITICALAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] orEPSS 3.7%CVE-2021-40408CRITICALAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] orEPSS 3.7%CVE-2024-20720CRITICALCommand injection in data collector backup due to insufficient patching of CVE-2023-38208EPSS 3.7%