Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2023-44829HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the AdminPassword parameter in the SetDeviceSettings function. TEPSS 0.9%CVE-2023-44836HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SSID parameter in the SetWLanRadioSettings function. This vuEPSS 0.9%CVE-2023-44830HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the EndTime parameter in the SetParentsControlInfo function. ThiEPSS 0.9%CVE-2023-44835HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vuEPSS 0.9%CVE-2023-44837HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Password parameter in the SetWanSettings function. This vulnEPSS 0.9%CVE-2023-44834HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the StartTime parameter in the SetParentsControlInfo function. TEPSS 0.9%CVE-2026-0836HIGHUTT 进取 520W formConfigFastDirectionW strcpy buffer overflowEPSS 0.9%CVE-2025-15459HIGHUTT 进取 520W formUser strcpy buffer overflowEPSS 0.9%CVE-2025-7747HIGHTenda FH451 POST Request WizardHandle fromWizardHandle buffer overflowEPSS 0.9%CVE-2026-48686CRITICALFastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) dEPSS 0.9%CVE-2026-49759HIGHStack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crashEPSS 0.9%CVE-2025-5156HIGHH3C GR-5400AX aspForm EditWlanMacList buffer overflowEPSS 0.9%CVE-2025-31700HIGHA vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted maliEPSS 0.9%CVE-2026-67858HIGHBuffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled throEPSS 0.9%CVE-2026-90780HIGHSIPp through 3.7.7 Buffer Overflow via Oversized SIP Header ContentEPSS 0.9%CVE-2026-90778HIGHSIPp through 3.7.7 Buffer Overflow via SIP To Header TagEPSS 0.9%CVE-2024-41660CRITICALslpd-lite unauthenticated memory corruptionEPSS 0.9%CVE-2025-7571HIGHUTT HiPER 840G aspApBasicConfigUrcp buffer overflowEPSS 0.9%CVE-2023-0612HIGHTRENDnet TEW-811DRU httpd basic.asp buffer overflowEPSS 0.9%CVE-2025-9303HIGHTOTOLINK A720R cstecgi.cgi setParentalRules buffer overflowEPSS 0.9%