Weaknesses of type CWE-77

2,817 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-22093HIGHAppliance mode iControl REST vulnerabilityEPSS 0.8%CVE-2026-73717HIGHUnauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.8%CVE-2026-47240MEDIUMNet::IMAP: Command Injection via non-synchronizing literal in "raw" argumentEPSS 0.8%CVE-2025-22472HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.8%CVE-2024-53290HIGHDell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An uEPSS 0.8%CVE-2025-69600HIGHCommand injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via getcoEPSS 0.8%CVE-2026-21516HIGHGitHub Copilot for Jetbrains Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-42025HIGHA Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and eaEPSS 0.8%CVE-2025-44179MEDIUMHitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due to improper input vEPSS 0.8%CVE-2024-45348MEDIUMXiaomi Router AX9000 has a post-authorization command injection vulnerabilityEPSS 0.8%CVE-2025-55590MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.EPSS 0.8%CVE-2024-53692MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2025-3621CRITICALRemote Code Execution in ProTNS ActADUREPSS 0.8%CVE-2024-41637HIGHRaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also posseEPSS 0.8%CVE-2024-57222MEDIUMLinksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps functiEPSS 0.8%CVE-2024-32282MEDIUMTenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.EPSS 0.8%CVE-2025-2983MEDIUMLegrand SMS PowerView os command injectionEPSS 0.8%CVE-2023-31476HIGHAn issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be creEPSS 0.8%CVE-2023-32700HIGHLuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs bEPSS 0.8%CVE-2025-65292HIGHCommand injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attEPSS 0.8%