Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-19792HIGHTenda G0 httpd web management interface module setPortMapping buffer overflowEPSS 0.9%CVE-2026-90606CRITICALTotolink A3002MU boa formIpv6Setup buffer overflowEPSS 0.9%CVE-2026-93738CRITICALTotolink A3002MU formSchedule buffer overflowEPSS 0.9%CVE-2024-37044MEDIUMQTS, QuTS heroEPSS 0.9%CVE-2026-93739CRITICALTotolink A3002MU formWlAc buffer overflowEPSS 0.9%CVE-2026-19821HIGHTenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflowEPSS 0.9%CVE-2026-86166HIGHTenda HG10 Boa Web Server formWanRedirect buffer overflowEPSS 0.9%CVE-2024-37041MEDIUMQTS, QuTS heroEPSS 0.9%CVE-2026-90608CRITICALTotolink A3002MU boa formPortFw buffer overflowEPSS 0.9%CVE-2026-85110HIGHTenda HG10 Boa Web Server formWlanSetup buffer overflowEPSS 0.9%CVE-2026-15543HIGHTenda CH22 CertListInfo formCertListInfo buffer overflowEPSS 0.9%CVE-2022-43365HIGHIP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function. This vulnerability allows attackerEPSS 0.9%CVE-2026-90605CRITICALTotolink A3002MU boa formFilter buffer overflowEPSS 0.9%CVE-2026-90607CRITICALTotolink A3002MU boa formNewSchedule buffer overflowEPSS 0.9%CVE-2021-0268HIGHJunos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks.EPSS 0.9%CVE-2026-1328HIGHTotolink NR1800X POST Request cstecgi.cgi setWizardCfg buffer overflowEPSS 0.9%CVE-2023-43504CRITICALA vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affecEPSS 0.9%CVE-2026-8764HIGHH3C Magic B3 aspForm UpdateWanParams buffer overflowEPSS 0.9%CVE-2023-50364MEDIUMQTS, QuTS heroEPSS 0.9%CVE-2023-26110HIGHAll versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user inputEPSS 0.9%