Weaknesses of type CWE-77

2,816 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2023-20045MEDIUMA vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticateEPSS 1.0%CVE-2024-48747MEDIUMAn issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.EPSS 1.0%CVE-2023-20124MEDIUMCisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers Remote Command Execution VulnerabilityEPSS 1.0%CVE-2024-49026HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 1.0%CVE-2025-45931CRITICALAn issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in tEPSS 1.0%CVE-2024-48214HIGHKERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. TEPSS 1.0%CVE-2026-23823HIGHAuthenticated Command Injection leads to RCE in AOS-10 CLI CommandEPSS 1.0%CVE-2020-26273MEDIUMsqlite ATTACH allows some filesystem accessEPSS 1.0%CVE-2025-33246HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection EPSS 1.0%CVE-2024-44610MEDIUMPCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters iEPSS 1.0%CVE-2026-9277CRITICALshell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`EPSS 1.0%CVE-2022-25855HIGHAll versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input saniEPSS 1.0%CVE-2023-52042HIGHAn issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lanEPSS 0.9%CVE-2025-22481HIGHQTS, QuTS heroEPSS 0.9%CVE-2025-22962HIGHA critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmittersEPSS 0.9%CVE-2023-23356MEDIUMQuFirewallEPSS 0.9%CVE-2024-38492CRITICALSymantec Privileged Access Manager Remote Command Execution vulnerabilityEPSS 0.9%CVE-2024-32349MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtuEPSS 0.9%CVE-2026-23815HIGHAuthenticated Command Injection found in AOS-CX Administrative CLI CommandEPSS 0.9%CVE-2025-44847MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanEPSS 0.9%