Weaknesses of type CWE-77

2,810 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2026-97366MEDIUMjhen0409 react-native-debugger Open in Editor window.js openDevTools os command injectionEPSS 1.2%CVE-2025-24285CRITICALMultiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with EPSS 1.2%CVE-2024-57233MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_dEPSS 1.1%CVE-2024-57230MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apclEPSS 1.1%CVE-2024-57231MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apclEPSS 1.1%CVE-2024-57234MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apclEPSS 1.1%CVE-2024-57235MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_eEPSS 1.1%CVE-2024-57232MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apclEPSS 1.1%CVE-2024-57229MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the resEPSS 1.1%CVE-2024-55461CRITICALSeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().EPSS 1.1%CVE-2025-59046CRITICALinteractive-git-checkout has Command Injection vulnerabilityEPSS 1.1%CVE-2026-21256HIGHGitHub Copilot and Visual Studio Remote Code Execution VulnerabilityEPSS 1.1%CVE-2024-30167MEDIUM/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a PEPSS 1.1%CVE-2024-20432CRITICALCisco Nexus Dashboard Fabric Controller Web UI Command Injection VulnerabilityEPSS 1.1%CVE-2023-1168HIGHAuthenticated Remote Code Execution in Aruba CX SwitchesEPSS 1.1%CVE-2026-23778HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 1.1%CVE-2026-31059CRITICALA remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackerEPSS 1.1%CVE-2025-5145MEDIUMNetcore POWER13 Query String cgi-bin command injectionEPSS 1.1%CVE-2025-5146MEDIUMNetcore NBR200V2 HTTP Header routerd passwd_set command injectionEPSS 1.1%CVE-2025-5147MEDIUMNetcore NBR1005GPEV2/NBR200V2/B6V2 network_tools tools_ping command injectionEPSS 1.1%