Weaknesses of type CWE-77

2,813 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-3539HIGHH3C Magic BE18000 HTTP POST Request getBasicInfo FCGI_CheckStringIfContainsSemicolon command injectionEPSS 1.1%CVE-2025-3540HIGHH3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request getCapability FCGI_WizardProtoProcess command injectionEPSS 1.1%CVE-2024-37570HIGHOn Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path paramEPSS 1.1%CVE-2023-0093HIGHOkta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowEPSS 1.1%CVE-2026-32194CRITICALMicrosoft Bing Images Remote Code Execution VulnerabilityEPSS 1.1%CVE-2023-51812CRITICALTenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlEPSS 1.1%CVE-2026-10180MEDIUMTRENDnet TEW-432BRP formSysCmd command injectionEPSS 1.1%CVE-2024-35241HIGHComposer vulnerable to command injection via malicious git branch nameEPSS 1.1%CVE-2026-12219MEDIUMYealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injectionEPSS 1.1%CVE-2023-51025HIGHTOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPEPSS 1.0%CVE-2023-51014HIGHTOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanEPSS 1.0%CVE-2024-35518HIGHNetgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.EPSS 1.0%CVE-2026-30898HIGHApache Airflow: Bad example of BashOperator shell injection via dag_run.confEPSS 1.0%CVE-2026-11341MEDIUMD-Link DWR-M920 formIMEISetup sub_412DA0 os command injectionEPSS 1.0%CVE-2025-53372HIGHnode-code-sandbox-mcp has a Sandbox Escape via Command InjectionEPSS 1.0%CVE-2026-11572HIGHVersions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of EPSS 1.0%CVE-2025-62214MEDIUMVisual Studio Remote Code Execution VulnerabilityEPSS 1.0%CVE-2024-32354MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSEPSS 1.0%CVE-2021-21406MEDIUMCommand Injection vulnerability in the Setup WizardEPSS 1.0%CVE-2024-39569HIGHA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications iEPSS 1.0%