Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-41485HIGHTenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47ce00 function. This vulnerabilityEPSS 0.9%CVE-2026-51808CRITICALBuffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::EPSS 0.9%CVE-2022-41481HIGHTenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47de1c function. This vulnerabilityEPSS 0.9%CVE-2022-41483HIGHTenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x4a12cc function. This vulnerabilityEPSS 0.9%CVE-2024-30584CRITICALTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.EPSS 0.9%CVE-2025-4299HIGHTenda AC1206 openSchedWifi setSchedWifi buffer overflowEPSS 0.8%CVE-2022-42273HIGHNVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.8%CVE-2025-4368HIGHTenda AC8 MtuSetMacWan formGetRouterStatus buffer overflowEPSS 0.8%CVE-2025-15091HIGHUTT 进取 512W formPictureUrl strcpy buffer overflowEPSS 0.8%CVE-2025-15092HIGHUTT 进取 512W ConfigExceptMSN strcpy buffer overflowEPSS 0.8%CVE-2025-7758HIGHTOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg buffer overflowEPSS 0.8%CVE-2025-7913HIGHTOTOLINK T6 MQTT Service updateWifiInfo buffer overflowEPSS 0.8%CVE-2025-8246HIGHTOTOLINK X15 HTTP POST Request formRoute buffer overflowEPSS 0.8%CVE-2022-46547CRITICALTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/VirtualSer.EPSS 0.8%CVE-2024-35099CRITICALTOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.EPSS 0.8%CVE-2023-25434HIGHlibtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.EPSS 0.8%CVE-2024-27619HIGHDlink Dir-3040us A1 1.20b03a hotfix is vulnerable to Buffer Overflow. Any user having read/write access to ftp server can write directly to EPSS 0.8%CVE-2023-28505HIGHBuffer overflow in UniRPC library functionEPSS 0.8%CVE-2021-33680MEDIUMSAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes bufferEPSS 0.8%CVE-2025-11300HIGHBelkin F9K1015 formWlanMP buffer overflowEPSS 0.8%