Falhas do tipo CWE-78
4.602 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2018-17558CRITICALHardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18EPSS 2.5%CVE-2018-1169—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User intEPSS 2.5%CVE-2026-28773CRITICALAuthenticated OS Command Injection via Ping Utility Leading to RCE as RootEPSS 2.5%CVE-2025-59834CRITICALCommand Injection in adb-mcp MCP ServerEPSS 2.5%CVE-2026-5679MEDIUMTotolink A3300R cstecgi.cgi vsetTr069Cfg os command injectionEPSS 2.5%CVE-2026-8500CRITICALWeb::Passwd versions through 0.03 for Perl is vulnerable to RCEEPSS 2.5%CVE-2018-5553CRITICALCrestron DGE-100 Console Command Injection (FIXED)EPSS 2.5%CVE-2022-45497CRITICALTenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommaEPSS 2.5%CVE-2022-45506CRITICALTenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.EPSS 2.5%CVE-2026-62392HIGHApache Kylin: OS Command Injection via Async Query APIEPSS 2.5%CVE-2026-53876HIGHRadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution witEPSS 2.5%CVE-2026-56808HIGHDGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execuEPSS 2.5%CVE-2020-3586CRITICALCisco DNA Spaces Connector Command Injection VulnerabilityEPSS 2.5%CVE-2024-21755HIGHA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 thEPSS 2.5%CVE-2026-22781CRITICALTinyWeb CGI Command InjectionEPSS 2.5%CVE-2026-2560MEDIUMkalcaddle kodbox Media File Preview Plugin VideoResize.class.php run os command injectionEPSS 2.5%CVE-2026-30861CRITICALWeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration ValidationEPSS 2.5%CVE-2026-71989CRITICALMSI Radix AXE6600 v781521 Command Injection via porTrigger functionEPSS 2.5%CVE-2026-71985CRITICALMSI Radix AXE6600 v781521 Command Injection via accesscontrol FunctionEPSS 2.5%CVE-2026-71987CRITICALMSI Radix AXE6600 v781521 Command Injection via alg functionEPSS 2.5%