Fallos del tipo CWE-77
2817 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2024-22093HIGHAppliance mode iControl REST vulnerabilityEPSS 0.8%CVE-2026-73717HIGHUnauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.8%CVE-2026-47240MEDIUMNet::IMAP: Command Injection via non-synchronizing literal in "raw" argumentEPSS 0.8%CVE-2025-22472HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.8%CVE-2024-53290HIGHDell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An uEPSS 0.8%CVE-2025-69600HIGHCommand injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via getcoEPSS 0.8%CVE-2026-21516HIGHGitHub Copilot for Jetbrains Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-42025HIGHA Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and eaEPSS 0.8%CVE-2025-44179MEDIUMHitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due to improper input vEPSS 0.8%CVE-2024-45348MEDIUMXiaomi Router AX9000 has a post-authorization command injection vulnerabilityEPSS 0.8%CVE-2025-55590MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.EPSS 0.8%CVE-2024-53692MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2025-3621CRITICALRemote Code Execution in ProTNS ActADUREPSS 0.8%CVE-2024-41637HIGHRaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also posseEPSS 0.8%CVE-2024-57222MEDIUMLinksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps functiEPSS 0.8%CVE-2024-32282MEDIUMTenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.EPSS 0.8%CVE-2025-2983MEDIUMLegrand SMS PowerView os command injectionEPSS 0.8%CVE-2023-31476HIGHAn issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be creEPSS 0.8%CVE-2023-32700HIGHLuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs bEPSS 0.8%CVE-2025-65292HIGHCommand injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attEPSS 0.8%