CWE-78 OS命令中使用的特殊元素转义处理不恰当(OS命令注入) 类弱点 2773 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-78即操作系统命令注入,属于输入验证缺陷。攻击者通过构造包含特殊字符的恶意输入,诱导程序拼接出非预期的系统命令,从而在服务器上执行任意代码。开发者应避免直接使用用户输入拼接命令,转而采用白名单过滤、参数化调用或安全API,确保外部数据仅作为参数而非命令结构的一部分,从根本上阻断注入路径。
$userName = $_POST["user"]; $command = 'ls -l /home/' . $userName; system($command);;rm -rf /int main(int argc, char** argv) { char cmd[CMD_MAX] = "/usr/bin/cat "; strcat(cmd, argv[1]); system(cmd); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-20617 | I-O Data Device UD-LT2 操作系统命令注入漏洞 — UD-LT2 | 6.7 | - | 2025-01-22 |
| CVE-2024-13502 | Newtec/iDirect NTC2218、Newtec/iDirect NTC2250和Newtec/iDirect NTC2299 操作系统命令注入漏洞 — NTC2218, NTC2250, NTC2299 | 7.2 | - | 2025-01-17 |
| CVE-2025-0457 | NetVision Information airPASS 操作系统命令注入漏洞 — airPASS | 8.8 | High | 2025-01-16 |
| CVE-2025-0356 | NEC Aterm WX1500HP 操作系统命令注入漏洞 — WX1500HP | 7.2 | High | 2025-01-15 |
| CVE-2024-26012 | Fortinet FortiAP 操作系统命令注入漏洞 — FortiAP-S | 6.3 | Medium | 2025-01-14 |
| CVE-2024-48890 | Fortinet FortiSOAR 操作系统命令注入漏洞 — FortiSOAR | 6.3 | Medium | 2025-01-14 |
| CVE-2024-40587 | Fortinet FortiVoice 操作系统命令注入漏洞 — FortiVoice | 6.3 | Medium | 2025-01-14 |
| CVE-2024-27778 | Fortinet FortiSandbox 操作系统命令注入漏洞 — FortiSandbox | 8.3 | High | 2025-01-14 |
| CVE-2023-37937 | Fortinet FortiSwitch 操作系统命令注入漏洞 — FortiSwitch | 7.6 | High | 2025-01-14 |
| CVE-2024-56497 | Fortinet FortiMail和FortiRecorder 操作系统命令注入漏洞 — FortiMail | 6.5 | Medium | 2025-01-14 |
| CVE-2024-50566 | Fortinet FortiManager 操作系统命令注入漏洞 — FortiManager | 7.2 | High | 2025-01-14 |
| CVE-2025-20055 | STEALTHONE D220和STEALTHONE D340 操作系统命令注入漏洞 — STEALTHONE D220 | 9.8 | Critical | 2025-01-14 |
| CVE-2025-20016 | STEALTHONE多款产品 操作系统命令注入漏洞 — STEALTHONE D220 | 7.2 | High | 2025-01-14 |
| CVE-2025-0107 | Palo Alto Networks Expedition 安全漏洞 — Cloud NGFW | 10.0 | - | 2025-01-11 |
| CVE-2024-12847 | NETGEAR DGN1000 安全漏洞 — DGN1000 | 9.8 | Critical | 2025-01-10 |
| CVE-2024-43653 | iocharger 安全漏洞 — Iocharger firmware for AC models | 8.8 | - | 2025-01-09 |
| CVE-2024-43654 | iocharger 安全漏洞 — Iocharger firmware for AC models | 8.8 | - | 2025-01-09 |
| CVE-2024-43651 | iocharger 安全漏洞 — Iocharger firmware for AC models | 8.8 | - | 2025-01-09 |
| CVE-2024-43649 | iocharger 安全漏洞 — Iocharger firmware for AC models | 8.8 | - | 2025-01-09 |
| CVE-2024-43657 | iocharger 安全漏洞 — Iocharger firmware for AC models | 7.8 | - | 2025-01-09 |
| CVE-2024-43648 | iocharger 安全漏洞 — Iocharger firmware for AC models | 8.8 | - | 2025-01-09 |
| CVE-2024-43656 | Iocharger 安全漏洞 — Iocharger firmware for AC models | 8.8 | - | 2025-01-09 |
| CVE-2024-43650 | iocharger 安全漏洞 — Iocharger firmware for AC models | 8.8 | - | 2025-01-09 |
| CVE-2024-43652 | iocharger 安全漏洞 — Iocharger firmware for AC chargers | 8.8 | - | 2025-01-09 |
| CVE-2024-43655 | iocharger 安全漏洞 — Iocharger firmware for AC models | 6.6 | - | 2025-01-09 |
| CVE-2024-50603 | Aviatrix Controller 操作系统命令注入漏洞 — Controller | 10.0 | Critical | 2025-01-08 |
| CVE-2024-11681 | MacPorts 操作系统命令注入漏洞 — MacPorts | 8.4 | - | 2025-01-07 |
| CVE-2024-12970 | TUBITAK BILGEM Pardus OS My Computer 操作系统命令注入漏洞 — Pardus OS My Computer | 3.9 | Low | 2025-01-06 |
| CVE-2024-13129 | Roxy-WI 操作系统命令注入漏洞 — Roxy-WI | 8.8 | High | 2025-01-03 |
| CVE-2024-9140 | MOXA多款产品 安全漏洞 — EDR-8010 Series | 9.8 | Critical | 2025-01-03 |
CWE-78(OS命令中使用的特殊元素转义处理不恰当(OS命令注入)) 是常见的弱点类别,本平台收录该类弱点关联的 2773 条 CVE 漏洞。