Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-67188CRITICALA buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg interface of the /liEPSS 0.7%CVE-2023-43314HIGH** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow EPSS 0.7%CVE-2022-39067MEDIUMThere is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interface, an authenticateEPSS 0.7%CVE-2026-24113CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When thEPSS 0.6%CVE-2026-24109CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. WhenEPSS 0.6%CVE-2026-24108CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When thEPSS 0.6%CVE-2026-24111CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. WhenEPSS 0.6%CVE-2023-1161MEDIUMISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or craEPSS 0.6%CVE-2024-36650HIGHTOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/EPSS 0.6%CVE-2025-6091HIGHH3C GR-3000AX aspForm UpdateIpv6Params buffer overflowEPSS 0.6%CVE-2023-47430MEDIUMStack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer(EPSS 0.6%CVE-2025-6090HIGHH3C GR-5400AX aspForm UpdateIpv6params buffer overflowEPSS 0.6%CVE-2024-52757LOWD-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.EPSS 0.6%CVE-2026-2086HIGHUTT HiPER 810G Management formFireWall strcpy buffer overflowEPSS 0.6%CVE-2024-37861CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl procEPSS 0.6%CVE-2023-22652LOWStack buffer overflow in "read_file" functionEPSS 0.6%CVE-2015-10123HIGHWago: Buffer Copy without Checking Size of Input in wbm of multiple productsEPSS 0.6%CVE-2023-45039LOWQTS, QuTS heroEPSS 0.6%CVE-2023-45043LOWQTS, QuTS heroEPSS 0.6%CVE-2023-45044LOWQTS, QuTS heroEPSS 0.6%