Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-10757HIGHUTT 1200GW formConfigDnsFilterGlobal buffer overflowEPSS 1.1%CVE-2025-7077HIGHShenzhen Libituo Technology LBT-T300-T310 appy.cgi config_3g_para buffer overflowEPSS 1.1%CVE-2023-22753HIGHUnauthenticated Buffer Overflow Vulnerabilities in ArubaOS ProcessesEPSS 1.1%CVE-2026-71958CRITICALD-Link DWR-M961 Buffer Overflow via quicksetup.cgiEPSS 1.1%CVE-2026-71957CRITICALD-Link DWR-M961 Buffer Overflow via app.cgiEPSS 1.1%CVE-2022-45995CRITICALThere is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to EPSS 1.1%CVE-2022-22570—A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malEPSS 1.1%CVE-2020-5213MEDIUMNetHack SYMBOL configuration file option is subject to a buffer overflowEPSS 1.1%CVE-2020-5212MEDIUMNetHack MENUCOLOR configuration file option is subject to a buffer overflowEPSS 1.1%CVE-2025-5911HIGHTOTOLINK EX1200T HTTP POST Request formDMZ buffer overflowEPSS 1.1%CVE-2025-5910HIGHTOTOLINK EX1200T HTTP POST Request formWsc buffer overflowEPSS 1.1%CVE-2023-39204MEDIUMBuffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.EPSS 1.1%CVE-2023-3725HIGHPotential buffer overflow vulnerability in the Zephyr CANbus subsystemEPSS 1.1%CVE-2021-42553MEDIUMSTM32 USB Host Library Buffer OverflowEPSS 1.1%CVE-2026-3701HIGHH3C Magic B1 aspForm Edit_BasicSSID_5G buffer overflowEPSS 1.1%CVE-2024-41285CRITICALA stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoSEPSS 1.1%CVE-2022-45714CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.EPSS 1.1%CVE-2022-45715CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the EPSS 1.1%CVE-2022-45718CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.EPSS 1.1%CVE-2022-45721CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.EPSS 1.1%