Falhas do tipo CWE-78
4.603 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-70329HIGHTOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd eEPSS 3.3%CVE-2022-33192CRITICALFour OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9EPSS 3.3%CVE-2022-33195CRITICALFour OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9EPSS 3.3%CVE-2022-33189CRITICALAn OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A EPSS 3.3%CVE-2022-32773CRITICALAn OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and EPSS 3.3%CVE-2024-9001MEDIUMTOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injectionEPSS 3.3%CVE-2023-4464HIGHPoly VVX 601 Diagnostic Telnet Mode os command injectionEPSS 3.3%CVE-2025-4032LOWinclusionAI AWorld shell_tool.py subprocess.Popen os command injectionEPSS 3.3%CVE-2025-7850CRITICALAuthenticated OS command executionEPSS 3.3%CVE-2026-25244CRITICALWebdriverIO has Command Injection in the BrowserStack ServiceEPSS 3.3%CVE-2021-3198MEDIUMIvanti MobileIron Core clish Restricted Shell Escape via OS Command InjectionEPSS 3.3%CVE-2020-13378HIGHLoadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to exEPSS 3.3%CVE-2026-2544MEDIUMyued-fe LuLu UI run.js child_process.exec os command injectionEPSS 3.3%CVE-2019-15979HIGHCisco Data Center Network Manager Command Injection VulnerabilitiesEPSS 3.3%CVE-2026-60121CRITICALVitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.phpEPSS 3.3%CVE-2022-31138HIGHOS Command Injection in mailcowEPSS 3.3%CVE-2021-24033—react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to be EPSS 3.3%CVE-2026-8986CRITICALCommand Injection via Malicious OCPP ServerEPSS 3.3%CVE-2026-41924CRITICALWDR201A WiFi Extender OS Command Injection via makeRequest.cgiEPSS 3.3%CVE-2026-82692CRITICALD-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injectionEPSS 3.3%