Fallos del tipo CWE-77
2831 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2026-102240CRITICALNetcore NAP930 Network Tools CGI network_tools eval os command injectionEPSS —CVE-2026-102827HIGHsimple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)EPSS —CVE-2026-102243MEDIUMMODSetter SurfSense MCP Connector Integration test command injectionEPSS —CVE-2026-101076CRITICALNetcore NR289-GE CGI set_ntp_server_ip.cgi system os command injectionEPSS —CVE-2026-101264CRITICALZiroom ZHOME A0101 set_passwd command injectionEPSS —CVE-2026-102826HIGHsimple-git allows command execution through unblocked Git configuration includesEPSS —CVE-2026-101072CRITICALNetcore NR289-GE CGI ap_ip.cgi system os command injectionEPSS —CVE-2026-101262CRITICALZiroom ZHOME A0101 set_online_client command injectionEPSS —CVE-2026-101187CRITICALZiroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injectionEPSS —CVE-2026-101859MEDIUMRaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injectionEPSS —CVE-2026-101260CRITICALZiroom ZHOME A0101 firstLogin command injectionEPSS —