Falhas do tipo CWE-77

2.822 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-32314LOWTenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.EPSS 1.0%CVE-2026-33111HIGHCopilot Chat (Microsoft Edge) Information Disclosure VulnerabilityEPSS 1.0%CVE-2024-29292CRITICALMultiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to exeEPSS 1.0%CVE-2025-2727HIGHH3C Magic NX30 Pro HTTP POST Request getNetworkStatus command injectionEPSS 1.0%CVE-2025-2732HIGHH3C Magic BE18000 HTTP POST Request getWifiNeighbour command injectionEPSS 1.0%CVE-2025-2726HIGHH3C Magic BE18000 HTTP POST Request esps command injectionEPSS 1.0%CVE-2025-44843MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function EPSS 1.0%CVE-2025-29743MEDIUMD-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.EPSS 1.0%CVE-2025-61044MEDIUMTOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMEPSS 1.0%CVE-2026-76231HIGHRenovate 32.135.0 before 40.33.0 Command Injection via hermitEPSS 1.0%CVE-2026-76232HIGHRenovate 31.51.0 before 40.33.0 Command Injection via helmv3EPSS 1.0%CVE-2026-76230HIGHRenovate 35.63.0 before 40.33.0 Command Injection via npmEPSS 1.0%CVE-2024-30220HIGHCommand injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute EPSS 1.0%CVE-2025-60683MEDIUMA command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specificallEPSS 1.0%CVE-2024-37782CRITICALAn LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or exeEPSS 1.0%CVE-2026-59721HIGHHoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injectionEPSS 1.0%CVE-2026-47299HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2025-24818HIGHAn OS Command Injection vulnerability in Nokia MantaRay NMEPSS 1.0%CVE-2023-26129HIGHAll versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwmEPSS 1.0%CVE-2026-76229HIGHRenovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomizeEPSS 1.0%