Falhas do tipo CWE-78

4.603 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-9384CRITICALTotolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injectionEPSS 3.3%CVE-2026-9476CRITICALTotolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injectionEPSS 3.3%CVE-2026-7139CRITICALTotolink A8000RU CGI cstecgi.cgi setWiFiAclRules os command injectionEPSS 3.3%CVE-2026-7138CRITICALTotolink A8000RU CGI cstecgi.cgi setNtpCfg os command injectionEPSS 3.3%CVE-2026-7155CRITICALTotolink A8000RU CGI cstecgi.cgi setLoginPasswordCfg os command injectionEPSS 3.3%CVE-2026-7121CRITICALTotolink A8000RU CGI cstecgi.cgi setWizardCfg os command injectionEPSS 3.3%CVE-2026-7244CRITICALTotolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injectionEPSS 3.3%CVE-2026-9475CRITICALTotolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injectionEPSS 3.3%CVE-2026-5996CRITICALTotolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow os command injectionEPSS 3.3%CVE-2026-5975CRITICALTotolink A7100RU CGI cstecgi.cgi setDmzCfg os command injectionEPSS 3.3%CVE-2026-9432CRITICALTotolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injectionEPSS 3.3%CVE-2026-6026CRITICALTotolink A7100RU CGI cstecgi.cgi setPortalConfWeChat os command injectionEPSS 3.3%CVE-2026-5854CRITICALTotolink A7100RU CGI cstecgi.cgi setWiFiEasyCfg os command injectionEPSS 3.3%CVE-2026-9433CRITICALTotolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injectionEPSS 3.3%CVE-2026-6195CRITICALTotolink A7100RU CGI cstecgi.cgi setPasswordCfg os command injectionEPSS 3.3%CVE-2026-7538CRITICALTotolink A8000RU CGI cstecgi.cgi vulnerability os command injectionEPSS 3.3%CVE-2026-7202CRITICALTotolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injectionEPSS 3.3%CVE-2023-43482HIGHA command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322EPSS 3.3%CVE-2019-1581CRITICALPAN-OS: Remote code execution vulnerability in the PAN-OS SSH device management interfaceEPSS 3.2%CVE-2025-30007HIGHHestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record ManagementEPSS 3.2%