Falhas do tipo CWE-78

4.609 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2023-6321HIGHOwlet Camera OS command injectionEPSS 2.7%CVE-2026-3841HIGHCommand Injection Vulnerability in Telnet CLI on TP-Link TL-MR6400EPSS 2.7%CVE-2025-50196HIGHChamilo: OS Command Injection in /plugin/vchamilo/views/editinstance.php via POST main_database parameterEPSS 2.7%CVE-2020-26274MEDIUMCommand Injection Vulnerability in systeminformationEPSS 2.7%CVE-2025-34184CRITICALIlevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauthenticated Code InjectionEPSS 2.7%CVE-2025-66210CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database ImportEPSS 2.7%CVE-2025-66211CRITICALCoolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script FilenameEPSS 2.7%CVE-2024-42740MEDIUMIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. AutheEPSS 2.7%CVE-2022-44928CRITICALD-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.EPSS 2.7%CVE-2024-1297HIGHLoomio 2.22.0 - Code injectionEPSS 2.7%CVE-2026-27563HIGHCommand Injection via GET in /api/datastorage/dataEPSS 2.7%CVE-2026-27560HIGHCommand Injection via DELETE in /api/status/dataEPSS 2.7%CVE-2026-86167CRITICALTenda HG10 Boa formgponConf os command injectionEPSS 2.7%CVE-2026-27562HIGHCommand Injection via PUT in /api/iodd/configEPSS 2.7%CVE-2026-27561HIGHCommand Injection via GET in /api/iodd/configEPSS 2.7%CVE-2026-27564HIGHCommand Injection via PUT in /api/datastorage/dataEPSS 2.7%CVE-2024-58376CRITICALRenovate 37.158.0 before 37.199.0 Command Injection via helmv3EPSS 2.7%CVE-2025-2096MEDIUMTOTOLINK EX1800T cstecgi.cgi setRebootScheCfg os command injectionEPSS 2.7%CVE-2019-12812—MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can beEPSS 2.7%CVE-2025-2095MEDIUMTOTOLINK EX1800T cstecgi.cgi setDmzCfg os command injectionEPSS 2.7%