Fallos del tipo CWE-77
2816 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2023-20045MEDIUMA vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticateEPSS 1.0%CVE-2024-48747MEDIUMAn issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.EPSS 1.0%CVE-2023-20124MEDIUMCisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers Remote Command Execution VulnerabilityEPSS 1.0%CVE-2024-49026HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 1.0%CVE-2025-45931CRITICALAn issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in tEPSS 1.0%CVE-2024-48214HIGHKERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. TEPSS 1.0%CVE-2026-23823HIGHAuthenticated Command Injection leads to RCE in AOS-10 CLI CommandEPSS 1.0%CVE-2020-26273MEDIUMsqlite ATTACH allows some filesystem accessEPSS 1.0%CVE-2025-33246HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection EPSS 1.0%CVE-2024-44610MEDIUMPCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters iEPSS 1.0%CVE-2026-9277CRITICALshell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`EPSS 1.0%CVE-2022-25855HIGHAll versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input saniEPSS 1.0%CVE-2023-52042HIGHAn issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lanEPSS 0.9%CVE-2025-22481HIGHQTS, QuTS heroEPSS 0.9%CVE-2025-22962HIGHA critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmittersEPSS 0.9%CVE-2023-23356MEDIUMQuFirewallEPSS 0.9%CVE-2024-38492CRITICALSymantec Privileged Access Manager Remote Command Execution vulnerabilityEPSS 0.9%CVE-2024-32349MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtuEPSS 0.9%CVE-2026-23815HIGHAuthenticated Command Injection found in AOS-CX Administrative CLI CommandEPSS 0.9%CVE-2025-44847MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanEPSS 0.9%