Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-20883MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.1%CVE-2022-20879MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.1%CVE-2022-20873MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.1%CVE-2026-86165CRITICALTenda HG10 formURL buffer overflowEPSS 1.1%CVE-2025-4140HIGHNetgear EX6120 sub_30394 buffer overflowEPSS 1.1%CVE-2025-4145HIGHNetgear EX6200 sub_3D0BC buffer overflowEPSS 1.1%CVE-2025-4142HIGHNetgear EX6200 sub_3C8EC buffer overflowEPSS 1.1%CVE-2026-7068HIGHD-Link DIR-825 nmbd sserver.c NMBD_process buffer overflowEPSS 1.1%CVE-2021-45423CRITICALA Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically allEPSS 1.1%CVE-2024-33454MEDIUMBuffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stacEPSS 1.1%CVE-2023-37457HIGHAsterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update'EPSS 1.1%CVE-2025-11299HIGHBelkin F9K1015 formWanTcpipSetup buffer overflowEPSS 1.1%CVE-2026-2980HIGHUTT HiPER 810G setSysAdm strcpy buffer overflowEPSS 1.1%CVE-2024-6142HIGHActiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.1%CVE-2024-6143HIGHActiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.1%CVE-2021-31845HIGHRemote Code Execution in McAfee DLP DiscoverEPSS 1.1%CVE-2020-5136—A buffer overflow vulnerability in SonicOS allows an authenticated attacker to cause Denial of Service (DoS) in the SSL-VPN and virtual assiEPSS 1.1%CVE-2025-12596HIGHTenda AC23 saveParentControlInfo buffer overflowEPSS 1.1%CVE-2025-3786HIGHTenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflowEPSS 1.1%CVE-2025-9962CRITICALUnauthenticated Buffer OverflowEPSS 1.1%