Fallos del tipo CWE-77
2810 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2025-7578LOWTeledyne FLIR FB-Series O/FLIR FH-Series ID runcmd.sh sendCommand command injectionEPSS 1.6%CVE-2023-22788HIGHAuthenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line InterfaceEPSS 1.6%CVE-2023-22790HIGHAuthenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line InterfaceEPSS 1.6%CVE-2023-20865HIGHVMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria EPSS 1.6%CVE-2023-26297HIGHPrevious versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.EPSS 1.6%CVE-2022-48338HIGHAn issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerEPSS 1.6%CVE-2023-26298HIGHPrevious versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.EPSS 1.6%CVE-2023-26296HIGHPrevious versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.EPSS 1.6%CVE-2026-79792MEDIUMzackees transcribe-anything Yt-dlp Download ytldp_download.py ytdlp_download os command injectionEPSS 1.6%CVE-2025-14276MEDIUMIlevia EVE X1 Server leaf_search.php command injectionEPSS 1.6%CVE-2024-43591HIGHAzure Command Line Integration (CLI) Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2025-11488MEDIUMD-Link DIR-852 HNAP1 command injectionEPSS 1.6%CVE-2025-50428CRITICALIn RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability isEPSS 1.6%CVE-2022-29560—A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < 2.15.1), RUGGEDCOM ROX MX5000RE (All versions < 2.15.1), RUGGEDCEPSS 1.6%CVE-2024-34852MEDIUMF-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transEPSS 1.6%CVE-2025-67089HIGHA command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.instEPSS 1.6%CVE-2026-11556HIGHTenda F451 Web Management WriteFacMac formWriteFacMac os command injectionEPSS 1.6%CVE-2024-3659CRITICALCommand injection in KAON AR2140 routersEPSS 1.6%CVE-2026-2256MEDIUMCommand injection vulnerability in ModelScope's ms-agentEPSS 1.6%CVE-2026-55182HIGHLibreNMS: Remote Code Execution by Signal Alert Transportation ModuleEPSS 1.6%