Falhas do tipo CWE-77

2.820 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-3545HIGHH3C Magic BE18000 HTTP POST Request setLanguage FCGI_CheckStringIfContainsSemicolon command injectionEPSS 1.1%CVE-2025-3539HIGHH3C Magic BE18000 HTTP POST Request getBasicInfo FCGI_CheckStringIfContainsSemicolon command injectionEPSS 1.1%CVE-2024-37570HIGHOn Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path paramEPSS 1.1%CVE-2023-0093HIGHOkta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowEPSS 1.1%CVE-2023-51812CRITICALTenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlEPSS 1.1%CVE-2026-32194CRITICALMicrosoft Bing Images Remote Code Execution VulnerabilityEPSS 1.1%CVE-2026-12219MEDIUMYealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injectionEPSS 1.1%CVE-2024-35241HIGHComposer vulnerable to command injection via malicious git branch nameEPSS 1.1%CVE-2026-10180MEDIUMTRENDnet TEW-432BRP formSysCmd command injectionEPSS 1.1%CVE-2023-51014HIGHTOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanEPSS 1.0%CVE-2023-51025HIGHTOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPEPSS 1.0%CVE-2024-35518HIGHNetgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.EPSS 1.0%CVE-2026-30898HIGHApache Airflow: Bad example of BashOperator shell injection via dag_run.confEPSS 1.0%CVE-2025-53372HIGHnode-code-sandbox-mcp has a Sandbox Escape via Command InjectionEPSS 1.0%CVE-2026-11341MEDIUMD-Link DWR-M920 formIMEISetup sub_412DA0 os command injectionEPSS 1.0%CVE-2026-11572HIGHVersions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of EPSS 1.0%CVE-2025-62214MEDIUMVisual Studio Remote Code Execution VulnerabilityEPSS 1.0%CVE-2024-32354MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSEPSS 1.0%CVE-2021-21406MEDIUMCommand Injection vulnerability in the Setup WizardEPSS 1.0%CVE-2024-32314LOWTenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.EPSS 1.0%