Falhas do tipo CWE-74

4.739 resultados

Injeção de código

Ocorre quando dados não confiáveis (entrada do usuário) são incorporados diretamente em comandos ou consultas executadas pelo sistema, sem validação ou escape. Um atacante consegue injetar código malicioso (SQL, script, comando) que será interpretado e executado com os privilégios da aplicação.

Exemplo

Uma busca por usuário que concatena a entrada diretamente em SQL: `SELECT * FROM users WHERE name = '` + input + `'`. Se o usuário digitar `' OR '1'='1`, a consulta retorna todos os registros. Com entrada maliciosa como `'; DROP TABLE users; --`, o banco é destruído.

Como mitigar

Use prepared statements ou queries parametrizadas (placeholders) para separar dados de código. Valide e sanitize todas as entradas, aplicando listas de permissão quando possível. Implemente o princípio do menor privilégio: a conta de banco de dados da aplicação deve ter apenas permissões necessárias.

CVE-2024-11653MEDIUMEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute command injectionEPSS 29.1%CVE-2024-11659MEDIUMEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_iperf command injectionEPSS 29.1%CVE-2024-11657MEDIUMEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_nslookup command injectionEPSS 29.1%CVE-2024-11656MEDIUMEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_ping6 command injectionEPSS 28.8%CVE-2024-11655MEDIUMEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_pinginterface command injectionEPSS 28.8%CVE-2025-5438MEDIUMLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 WPS command injectionEPSS 27.8%CVE-2024-11651MEDIUMEnGenius ENH1350EXT/ENS500-AC/ENS620EXT wifi_schedule command injectionEPSS 27.4%CVE-2025-9769LOWD-Link DI-7400G+ mng_platform.asp sub_478D28 command injectionEPSS 27.0%CVE-2024-10697MEDIUMTenda AC6 API Endpoint WriteFacMac formWriteFacMac command injectionEPSS 26.2%CVE-2026-2537MEDIUMComfast CF-E4 HTTP POST Request mbox-config command injectionEPSS 25.3%CVE-2024-21645MEDIUMpyLoad Log InjectionEPSS 24.7%CVE-2026-4197MEDIUMD-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injectionEPSS 23.7%CVE-2025-7952MEDIUMTOTOLINK T6 MQTT Packet wireless.so ckeckKeepAlive command injectionEPSS 20.9%CVE-2024-21797CRITICALA command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted EPSS 20.8%CVE-2024-36295CRITICALA command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTEPSS 20.8%CVE-2025-4341MEDIUMD-Link DIR-880L Request Header ssdpcgi sub_16570 command injectionEPSS 20.7%CVE-2025-8956MEDIUMD-Link DIR‑818L ssdpcgi cgibin getenv command injectionEPSS 20.5%CVE-2021-41163CRITICALRCE via malicious SNS subscription payloadEPSS 19.8%CVE-2025-13442MEDIUMUTT 进取 750W formPdbUpConfig system command injectionEPSS 19.5%CVE-2025-14707CRITICALShiguangwu sgwbox N3 DOCKER Feature http_eshell_server command injectionEPSS 18.6%