Weaknesses of type CWE-77

2,816 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-6257HIGHHashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config ManipulationEPSS 1.0%CVE-2025-63749MEDIUMpnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.EPSS 1.0%CVE-2024-42947CRITICALAn issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafEPSS 1.0%CVE-2023-23917HIGHA prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any uEPSS 1.0%CVE-2024-31811HIGHTOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in thEPSS 1.0%CVE-2024-44574HIGHRELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.EPSS 1.0%CVE-2025-4231HIGHPAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web InterfaceEPSS 1.0%CVE-2024-44572HIGHRELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.EPSS 1.0%CVE-2026-30310CRITICALIn its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The descriEPSS 1.0%CVE-2023-36755CRITICALA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEEPSS 1.0%CVE-2025-3008MEDIUMNovastar CX40 NetFilter Utility netconfig popen command injectionEPSS 1.0%CVE-2023-5878CRITICALOneWireless command injection possible when updating firmwareEPSS 1.0%CVE-2023-21778HIGHMicrosoft Dynamics Unified Service Desk Remote Code Execution VulnerabilityEPSS 1.0%CVE-2023-41282MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-41281MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-41283MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-47563HIGHVideo StationEPSS 1.0%CVE-2026-24168MEDIUMNVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may causeEPSS 1.0%CVE-2025-58358HIGHMarkdownify is vulnerable to command injection through pptx-to-markdown toolEPSS 1.0%CVE-2024-48747MEDIUMAn issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.EPSS 1.0%