Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2023-38823CRITICALBuffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code vEPSS 1.2%CVE-2022-20888MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.2%CVE-2024-7337HIGHTOTOLINK EX1200L cstecgi.cgi loginauth buffer overflowEPSS 1.2%CVE-2024-7331HIGHTOTOLINK A3300R cstecgi.cgi UploadCustomModule buffer overflowEPSS 1.2%CVE-2024-7338HIGHTOTOLINK EX1200L cstecgi.cgi setParentalRules buffer overflowEPSS 1.2%CVE-2021-1493HIGHCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Buffer Overflow Denial of Service VulnerabilityEPSS 1.2%CVE-2026-6013HIGHD-Link DIR-513 POST Request formSetRoute buffer overflowEPSS 1.2%CVE-2022-20891MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.2%CVE-2025-4343HIGHD-Link DIR-600L formEasySetupWizard buffer overflowEPSS 1.2%CVE-2025-4342HIGHD-Link DIR-600L formEasySetupWizard3 buffer overflowEPSS 1.2%CVE-2025-1897HIGHTenda TX3 SetNetControlList buffer overflowEPSS 1.2%CVE-2024-7334HIGHTOTOLINK EX1200L cstecgi.cgi UploadCustomModule buffer overflowEPSS 1.2%CVE-2022-39244HIGHBuffer overflow in pjlib scanner and pjmediaEPSS 1.2%CVE-2023-3618MEDIUMSegmentation fault in fax3encode in libtiff/tif_fax3.cEPSS 1.2%CVE-2026-7855HIGHD-Link DI-8100 HTTP Request tggl.asp tggl_asp buffer overflowEPSS 1.2%CVE-2023-20157HIGHCisco Small Business Series Switches Buffer Overflow VulnerabilitiesEPSS 1.2%CVE-2023-20162HIGHCisco Small Business Series Switches Buffer Overflow VulnerabilitiesEPSS 1.2%CVE-2023-20158HIGHCisco Small Business Series Switches Buffer Overflow VulnerabilitiesEPSS 1.2%CVE-2023-20156HIGHCisco Small Business Series Switches Buffer Overflow VulnerabilitiesEPSS 1.2%CVE-2024-24736HIGHThe POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related issueEPSS 1.2%