Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-25664CRITICALTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.EPSS 0.6%CVE-2026-36811HIGHShenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picName parameter of the formDeEPSS 0.6%CVE-2026-36796HIGHShenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the picCropName parameter of the formCrEPSS 0.6%CVE-2026-36818HIGHShenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter ofEPSS 0.6%CVE-2026-36801HIGHShenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBindRule parameter of the forEPSS 0.6%CVE-2026-36809HIGHShenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteID parameter of theEPSS 0.6%CVE-2026-36815HIGHShenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSEPSS 0.6%CVE-2026-7287HIGH** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and foEPSS 0.6%CVE-2024-34905HIGHFlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackersEPSS 0.6%CVE-2024-46424HIGHTOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to EPSS 0.6%CVE-2025-3496HIGHAUMA Riester: Buffer overflow in service telegramEPSS 0.6%CVE-2024-31504HIGHBuffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service EPSS 0.6%CVE-2026-38426HIGHBuffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scEPSS 0.5%CVE-2024-37607MEDIUMA Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a craftEPSS 0.5%CVE-2024-57480CRITICALH3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. AttackersEPSS 0.5%CVE-2024-48984CRITICALAn issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list ofEPSS 0.5%CVE-2024-57479CRITICALH3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. AttackeEPSS 0.5%CVE-2023-32972LOWQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-32971LOWQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-41275MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%