Falhas do tipo CWE-77

2.825 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-48747MEDIUMAn issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.EPSS 1.0%CVE-2023-20045MEDIUMA vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticateEPSS 1.0%CVE-2024-49026HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 1.0%CVE-2025-45931CRITICALAn issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in tEPSS 1.0%CVE-2023-20124MEDIUMCisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers Remote Command Execution VulnerabilityEPSS 1.0%CVE-2024-48214HIGHKERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. TEPSS 1.0%CVE-2026-23823HIGHAuthenticated Command Injection leads to RCE in AOS-10 CLI CommandEPSS 1.0%CVE-2025-33246HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection EPSS 1.0%CVE-2020-26273MEDIUMsqlite ATTACH allows some filesystem accessEPSS 1.0%CVE-2024-44610MEDIUMPCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters iEPSS 1.0%CVE-2026-9277CRITICALshell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`EPSS 1.0%CVE-2022-25855HIGHAll versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input saniEPSS 1.0%CVE-2023-52042HIGHAn issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lanEPSS 0.9%CVE-2025-22481HIGHQTS, QuTS heroEPSS 0.9%CVE-2025-22962HIGHA critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmittersEPSS 0.9%CVE-2023-23356MEDIUMQuFirewallEPSS 0.9%CVE-2024-32349MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtuEPSS 0.9%CVE-2024-38492CRITICALSymantec Privileged Access Manager Remote Command Execution vulnerabilityEPSS 0.9%CVE-2026-23815HIGHAuthenticated Command Injection found in AOS-CX Administrative CLI CommandEPSS 0.9%CVE-2026-11455LOWFoundationAgents MetaGPT common.py check_cmd_exists command injectionEPSS 0.9%