Falhas do tipo CWE-78

4.603 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-82689CRITICALD-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injectionEPSS 3.3%CVE-2026-41924CRITICALWDR201A WiFi Extender OS Command Injection via makeRequest.cgiEPSS 3.3%CVE-2026-90699CRITICALD-Link DWR-M920 formPinManageSetup sub_41E60C os command injectionEPSS 3.3%CVE-2026-71966HIGHCyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransferEPSS 3.3%CVE-2025-56094HIGHOS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POSTEPSS 3.3%CVE-2025-1369LOWMicroWord eScan Antivirus USB Password os command injectionEPSS 3.3%CVE-2019-10958—Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote auEPSS 3.3%CVE-2026-42364CRITICALGeoVision LPC2011/LPC2211 Web Interface / DdnsSetting.cgi OS command injection vulnerabilityEPSS 3.3%CVE-2026-69096HIGHOpenWrt luci-app-dockerman Read ACL Remote Code ExecutionEPSS 3.3%CVE-2026-60102HIGHHorde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb DriverEPSS 3.3%CVE-2025-59361CRITICALOS command injection in Chaos Mesh via the cleanIptables mutationEPSS 3.3%CVE-2025-3729MEDIUMSourceCodester Web-based Pharmacy Product Management System Database Backup backup.php os command injectionEPSS 3.3%CVE-2022-30541CRITICALAn OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and EPSS 3.3%CVE-2026-82004CRITICALAdobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 3.3%CVE-2026-9458CRITICALTotolink A8000RU Web Management cstecgi.cgi setWanCfg os command injectionEPSS 3.3%CVE-2026-7204CRITICALTotolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injectionEPSS 3.3%CVE-2026-7140CRITICALTotolink A8000RU CGI cstecgi.cgi CsteSystem os command injectionEPSS 3.3%CVE-2026-9408CRITICALTotolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injectionEPSS 3.3%CVE-2026-9406CRITICALTotolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injectionEPSS 3.3%CVE-2026-6028CRITICALTotolink A7100RU CGI cstecgi.cgi setPptpServerCfg os command injectionEPSS 3.3%