Weaknesses of type CWE-77

2,816 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2022-20925MEDIUMA vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remoteEPSS 0.9%CVE-2026-21257HIGHGitHub Copilot and Visual Studio Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2025-44844MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileNameEPSS 0.9%CVE-2025-44841MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function EPSS 0.9%CVE-2025-44840MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function EPSS 0.9%CVE-2025-44860MEDIUMTOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port paramEPSS 0.9%CVE-2025-44848MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url paramEPSS 0.9%CVE-2025-44842MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port paraEPSS 0.9%CVE-2025-44845MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTEPSS 0.9%CVE-2025-44863MEDIUMTOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameEPSS 0.9%CVE-2025-44839MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function EPSS 0.9%CVE-2021-31356HIGHJunos OS Evolved: Multiple shell-injection vulnerabilities in EVO UI wrapper scriptsEPSS 0.9%CVE-2022-36769HIGHIBM Cloud Pak for Data file uploadEPSS 0.9%CVE-2026-48561CRITICALMicrosoft Edge Copilot Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-49179HIGHWindows Active Directory Domain Services Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-45800CRITICALTOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/gEPSS 0.9%CVE-2018-0217—A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenEPSS 0.9%CVE-2023-38690MEDIUMmatrix-appservice-irc IRC command injection via admin commands containing newlines EPSS 0.9%CVE-2026-35428CRITICALAzure Cloud Shell Spoofing VulnerabilityEPSS 0.9%CVE-2026-84190HIGHLibreNMS before 26.5.0 Remote Code Execution via AboutControllerEPSS 0.9%