Fallos del tipo CWE-77

2810 resultados

Injeção de comando via entrada não sanitizada

O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.

Ejemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.

Cómo mitigar

Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.

CVE-2026-38945HIGHCommand injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted pathEPSS 1.2%CVE-2022-32664HIGHIn Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilegeEPSS 1.2%CVE-2026-13501MEDIUMantlr ANTLR4 gofmt GoTarget.java GoTarget command injectionEPSS 1.2%CVE-2022-32203CRITICALThere is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privilegeEPSS 1.2%CVE-2025-28017MEDIUMTOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.EPSS 1.2%CVE-2025-50526CRITICALNetgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.EPSS 1.2%CVE-2025-57685HIGHThe LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, anEPSS 1.2%CVE-2026-7039HIGHtufantunc ssh-mcp index.ts shell.write command injectionEPSS 1.2%CVE-2024-44916HIGHVulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/adminEPSS 1.2%CVE-2025-27083HIGHAuthenticated Command Injection Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 1.2%CVE-2024-38896MEDIUMWAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.EPSS 1.2%CVE-2021-22867—Unsafe configuration options in GitHub Pages leading to path traversal on GitHub Enterprise ServerEPSS 1.2%CVE-2025-46428HIGHDell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('CommEPSS 1.2%CVE-2024-6333HIGHAuthenticated Remote Code Execution in Altalink, Versalink & WorkCentre ProductsEPSS 1.2%CVE-2024-23049CRITICALAn issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.EPSS 1.2%CVE-2025-4747MEDIUMBohua NetDragon Firewall ip_status.php command injectionEPSS 1.2%CVE-2021-41144HIGHOpenMage LTS authenticated remote code execution through layout updateEPSS 1.2%CVE-2024-0817CRITICALCommand injection in IrGraph.draw in paddlepaddle/paddle 2.6.0EPSS 1.2%CVE-2026-94139MEDIUMChengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injectionEPSS 1.2%CVE-2024-27981CRITICALA Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and eaEPSS 1.2%