Weaknesses of type CWE-77

2,813 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-32314LOWTenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.EPSS 1.0%CVE-2024-29292CRITICALMultiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to exeEPSS 1.0%CVE-2026-33111HIGHCopilot Chat (Microsoft Edge) Information Disclosure VulnerabilityEPSS 1.0%CVE-2025-2726HIGHH3C Magic BE18000 HTTP POST Request esps command injectionEPSS 1.0%CVE-2025-2732HIGHH3C Magic BE18000 HTTP POST Request getWifiNeighbour command injectionEPSS 1.0%CVE-2025-2727HIGHH3C Magic NX30 Pro HTTP POST Request getNetworkStatus command injectionEPSS 1.0%CVE-2025-44843MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function EPSS 1.0%CVE-2025-29743MEDIUMD-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.EPSS 1.0%CVE-2025-61044MEDIUMTOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMEPSS 1.0%CVE-2026-76231HIGHRenovate 32.135.0 before 40.33.0 Command Injection via hermitEPSS 1.0%CVE-2026-76232HIGHRenovate 31.51.0 before 40.33.0 Command Injection via helmv3EPSS 1.0%CVE-2026-76230HIGHRenovate 35.63.0 before 40.33.0 Command Injection via npmEPSS 1.0%CVE-2024-30220HIGHCommand injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute EPSS 1.0%CVE-2025-60683MEDIUMA command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specificallEPSS 1.0%CVE-2024-37782CRITICALAn LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or exeEPSS 1.0%CVE-2026-59721HIGHHoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injectionEPSS 1.0%CVE-2026-47299HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2025-24818HIGHAn OS Command Injection vulnerability in Nokia MantaRay NMEPSS 1.0%CVE-2023-26129HIGHAll versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwmEPSS 1.0%CVE-2025-2728HIGHH3C Magic NX30 Pro/Magic NX400 getNetworkConf command injectionEPSS 1.0%