Falhas do tipo CWE-77

2.823 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-76233HIGHRenovate 39.53.0 before 40.33.0 Command Injection via gleam managerEPSS 1.0%CVE-2025-2729HIGHH3C Magic BE18000 HTTP POST Request networkSetup command injectionEPSS 1.0%CVE-2025-2731HIGHH3C Magic BE18000 HTTP POST Request getDualbandSync command injectionEPSS 1.0%CVE-2025-2730HIGHH3C Magic BE18000 HTTP POST Request getssidname command injectionEPSS 1.0%CVE-2026-76229HIGHRenovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomizeEPSS 1.0%CVE-2020-5299MEDIUMPotential CSV Injection vector in OctoberCMSEPSS 1.0%CVE-2024-44577HIGHRELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.EPSS 1.0%CVE-2024-52022HIGHNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerabEPSS 1.0%CVE-2026-22317HIGHCommand Injection Vulnerability in Root CA Certificate Transfer WorkflowEPSS 1.0%CVE-2024-36983HIGHCommand Injection using External LookupsEPSS 1.0%CVE-2026-56197HIGHWindows Admin Center (WAC) Remote Code Execution VulnerabilityEPSS 1.0%CVE-2022-25962HIGHAll versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization. EPSS 1.0%CVE-2023-26127HIGHAll versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. *EPSS 1.0%CVE-2025-61489MEDIUMA command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands viaEPSS 1.0%CVE-2024-8640HIGHImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 1.0%CVE-2024-3483HIGHRemote Code Execution vulnerability in the iManagerEPSS 1.0%CVE-2024-13062HIGHAn unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. ReferEPSS 1.0%CVE-2026-22284MEDIUMDell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements used in a Command ('ComEPSS 1.0%CVE-2024-6257HIGHHashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config ManipulationEPSS 1.0%CVE-2025-57282HIGHngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.EPSS 1.0%