Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-5862HIGHTenda AC7 setPptpUserList formSetPPTPUserList buffer overflowEPSS 1.0%CVE-2025-12234HIGHTenda CH22 SafeMacFilter fromSafeMacFilter buffer overflowEPSS 1.0%CVE-2022-24788HIGHBuffer overflow in VyperEPSS 1.0%CVE-2026-4565HIGHTenda AC21 SetNetControlList formSetQosBand buffer overflowEPSS 1.0%CVE-2023-24019HIGHA stack-based buffer overflow vulnerability exists in the urvpn_client http_connection_readcb functionality of Milesight UR32L v32.3.0.5. A EPSS 1.0%CVE-2026-1139HIGHUTT 进取 520W ConfigExceptMSN strcpy buffer overflowEPSS 1.0%CVE-2026-1138HIGHUTT 进取 520W ConfigExceptQQ strcpy buffer overflowEPSS 1.0%CVE-2020-6999—In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text is the correct size EPSS 1.0%CVE-2022-36361CRITICALA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versionEPSS 1.0%CVE-2006-6024CRITICALMultiple buffer overflows in Eudora Worldmail, possibly Worldmail 3 version 6.1.22.0, have unknown impact and attack vectors, as demonstrateEPSS 1.0%CVE-2024-9783HIGHD-Link DIR-619L B1 formLogDnsquery buffer overflowEPSS 1.0%CVE-2024-9784HIGHD-Link DIR-619L B1 formResetStatistic buffer overflowEPSS 1.0%CVE-2025-29329CRITICALBuffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute EPSS 1.0%CVE-2026-1137HIGHUTT 进取 520W formWebAuthGlobalConfig strcpy buffer overflowEPSS 1.0%CVE-2025-66647LOWRIOT OS has buffer overflow in gnrc_ipv6_ext_frag_reassEPSS 1.0%CVE-2025-11305HIGHUTT HiPER 840G formTaskEdit strcpy buffer overflowEPSS 1.0%CVE-2025-46060CRITICALBuffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILEPSS 1.0%CVE-2024-33453HIGHBuffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component.EPSS 1.0%CVE-2022-20687MEDIUMMultiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmwareEPSS 1.0%CVE-2023-26319MEDIUMXiaomi Router administration interface vulnerability leads command injection and stack overflowEPSS 1.0%