Falhas do tipo CWE-77

2.820 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-29063CRITICALAn issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hiEPSS 1.1%CVE-2025-29062CRITICALAn issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_EPSS 1.1%CVE-2025-26056MEDIUMA command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability iEPSS 1.1%CVE-2024-42427HIGHDell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerabEPSS 1.1%CVE-2026-11447MEDIUMGL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injectionEPSS 1.1%CVE-2026-10166MEDIUMEdimax BR-6478AC POST Request formWlbasic command injectionEPSS 1.1%CVE-2026-10182MEDIUMTRENDnet TEW-432BRP formWlanSetup command injectionEPSS 1.1%CVE-2022-43623MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2025-55911MEDIUMAn issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameterEPSS 1.1%CVE-2026-94031MEDIUM0-Gaurav-0 nexus-mcp nexus_reauth MCP tool browser.ts child_process.exec command injectionEPSS 1.1%CVE-2026-10550MEDIUMelunez eladmin Application Deployment App.java command injectionEPSS 1.1%CVE-2026-38142MEDIUMAn unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attacEPSS 1.1%CVE-2026-19282MEDIUMandreahaku llm_memory_mcp GitHooksManager.ts auto.capture command injectionEPSS 1.1%CVE-2026-16733MEDIUMbahmutov find-cypress-specs Branch index.js shell.exec os command injectionEPSS 1.1%CVE-2026-2333CRITICALImproper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opdsEPSS 1.1%CVE-2025-3540HIGHH3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request getCapability FCGI_WizardProtoProcess command injectionEPSS 1.1%CVE-2025-3541HIGHH3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request getSpecs FCGI_WizardProtoProcess command injectionEPSS 1.1%CVE-2025-3544HIGHH3C Magic BE18000 HTTP POST Request getCapabilityWeb FCGI_CheckStringIfContainsSemicolon command injectionEPSS 1.1%CVE-2025-3545HIGHH3C Magic BE18000 HTTP POST Request setLanguage FCGI_CheckStringIfContainsSemicolon command injectionEPSS 1.1%CVE-2025-3539HIGHH3C Magic BE18000 HTTP POST Request getBasicInfo FCGI_CheckStringIfContainsSemicolon command injectionEPSS 1.1%