Weaknesses of type CWE-77

2,816 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-5023CRITICALArbitrary File Read Vulnerability in ConsoleMe via Limited Git command RCEEPSS 0.9%CVE-2025-44838MEDIUMTOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via thEPSS 0.9%CVE-2025-44836MEDIUMTOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via tEPSS 0.9%CVE-2025-44861MEDIUMTOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function vEPSS 0.9%CVE-2025-44837MEDIUMTOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck funcEPSS 0.9%CVE-2025-44854MEDIUMTOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName EPSS 0.9%CVE-2026-11455LOWFoundationAgents MetaGPT common.py check_cmd_exists command injectionEPSS 0.9%CVE-2023-46687CRITICALEmerson Rosemount GC370XA, GC700XA, GC1500XA Command InjectionEPSS 0.9%CVE-2025-44847MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanEPSS 0.9%CVE-2025-44846MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrEPSS 0.9%CVE-2017-12335—A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attackEPSS 0.9%CVE-2025-54424HIGH1Panel Agent Bypasses Certificate Verification Leading to Arbitrary Command ExecutionEPSS 0.9%CVE-2022-48259CRITICALThere is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher EPSS 0.9%CVE-2021-22868—Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise ServerEPSS 0.9%CVE-2026-20095MEDIUMCisco Integrated Management Controller Command Injection VulnerabilityEPSS 0.9%CVE-2024-26295HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-26294HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2026-30352CRITICALA remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execuEPSS 0.9%CVE-2025-7388HIGHAuthenticated Command Injection via configuration parameter manipulation in exposed RMI interfaceEPSS 0.9%CVE-2026-72735CRITICALDokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote executionEPSS 0.9%