Falhas do tipo CWE-78

4.603 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-5972MEDIUMFoundationAgents MetaGPT terminal.py Terminal.run_command os command injectionEPSS 3.5%CVE-2026-25512CRITICALGroup-Office is vulnerable to RCE due to Command Injection via TNEF Attachment HandlerEPSS 3.5%CVE-2020-8270—An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 EPSS 3.5%CVE-2026-0755CRITICALgemini-mcp-tool execAsync Command Injection Remote Code Execution VulnerabilityEPSS 3.5%CVE-2022-42490CRITICALSeveral OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted netwEPSS 3.5%CVE-2022-34850CRITICALAn OS command injection vulnerability exists in the web_server /action/import_authorized_keys/ functionality of Robustel R1510 3.1.16 and 3.EPSS 3.5%CVE-2013-10073HIGHNagios XI < 2012R1.6 Auto-Discovery Shell Command InjectionEPSS 3.5%CVE-2025-56088HIGHOS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request toEPSS 3.5%CVE-2026-5973MEDIUMFoundationAgents MetaGPT common.py get_mime_type os command injectionEPSS 3.5%CVE-2026-5974MEDIUMFoundationAgents MetaGPT terminal.py Bash.run os command injectionEPSS 3.5%CVE-2026-9436CRITICALTotolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injectionEPSS 3.5%CVE-2022-33150CRITICALAn OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network rEPSS 3.4%CVE-2026-33623MEDIUMPinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command ExecutionEPSS 3.4%CVE-2023-47209HIGHA post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.EPSS 3.4%CVE-2023-42664HIGHA post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VEPSS 3.4%CVE-2023-47617HIGHA post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN RouteEPSS 3.4%CVE-2023-47167HIGHA post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.EPSS 3.4%CVE-2023-46683HIGHA post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada GigabEPSS 3.4%CVE-2023-36498HIGHA post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3EPSS 3.4%CVE-2021-36022CRITICALMagento Commerce Widgets Update Layout XML Injection Vulnerability Could Lead To Remote Code ExecutionEPSS 3.4%