Falhas do tipo CWE-78
4.607 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-44342HIGHD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This EPSS 2.0%CVE-2026-53479HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 2.0%CVE-2026-20764HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 2.0%CVE-2024-5291HIGHD-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2024-5295HIGHD-Link G416 flupl self Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2025-15063CRITICALOllama MCP Server execAsync Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2022-44844CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setEPSS 2.0%CVE-2022-44843CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setEPSS 2.0%CVE-2021-28203HIGHASUS BMC's firmware: command injection - Web Set Media Image functionEPSS 2.0%CVE-2022-48124CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the settingEPSS 2.0%CVE-2022-48126CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the settingEPSS 2.0%CVE-2022-48122CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the settingEPSS 2.0%CVE-2022-48125CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the settingEPSS 2.0%CVE-2022-48121CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/EPSS 2.0%CVE-2022-48123CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the settiEPSS 2.0%CVE-2026-32260HIGHCommand Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)EPSS 2.0%CVE-2026-16348HIGHCommand Injection Vulnerability in VPN connection of Archer BE800EPSS 2.0%CVE-2026-74770HIGHDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS CommanEPSS 2.0%CVE-2005-10004HIGHCacti graph_view.php RCE via graph_start Parameter InjectionEPSS 2.0%CVE-2026-72589CRITICALalseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook FieldEPSS 1.9%