Falhas do tipo CWE-78
4.608 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2021-4144—TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.EPSS 1.9%CVE-2025-23049HIGHMeridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.EPSS 1.9%CVE-2023-47618HIGHA post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1EPSS 1.9%CVE-2026-34594HIGHCoolify: Authenticated Remote Code Execution via Command Injection in Destination Network ManagementEPSS 1.9%CVE-2021-3723HIGHA command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 365EPSS 1.9%CVE-2024-25851HIGHNetis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgiteEPSS 1.9%CVE-2024-43652CRITICALAuthenticated command injection in the <redacted> action leads to full remote code execution as root on the charging stationEPSS 1.9%CVE-2022-22273—Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) pEPSS 1.9%CVE-2026-25105HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.9%CVE-2026-24452HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.9%CVE-2026-23702HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.9%CVE-2026-25196HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.9%CVE-2026-25037HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.9%CVE-2023-50383HIGHThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially craftedEPSS 1.9%CVE-2023-27917HIGHOS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network MaintenanEPSS 1.9%CVE-2023-50382HIGHThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially craftedEPSS 1.9%CVE-2024-5297HIGHD-Link D-View executeWmicCmd Command Injection Remote Code Execution VulnerabilityEPSS 1.9%CVE-2019-1010200—Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: EPSS 1.9%CVE-2021-32533CRITICALQSAN SANOS - Command InjectionEPSS 1.9%CVE-2021-32534CRITICALQSAN SANOS - Command InjectionEPSS 1.9%