Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-57222MEDIUMLinksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps functiEPSS 0.8%CVE-2024-32282MEDIUMTenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.EPSS 0.8%CVE-2025-2983MEDIUMLegrand SMS PowerView os command injectionEPSS 0.8%CVE-2023-32700HIGHLuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs bEPSS 0.8%CVE-2023-31476HIGHAn issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be creEPSS 0.8%CVE-2025-65292HIGHCommand injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attEPSS 0.8%CVE-2024-21903MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2025-33180HIGHNVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A EPSS 0.8%CVE-2026-22708HIGHCursor has a Terminal Tool Allowlist Bypass via Environment VariablesEPSS 0.8%CVE-2024-46084HIGHScriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.EPSS 0.8%CVE-2023-26429LOWControl characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedEPSS 0.8%CVE-2025-25604MEDIUMTotolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.EPSS 0.8%CVE-2025-25605MEDIUMTotolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.EPSS 0.8%CVE-2026-22785CRITICALorval MCP client is vulnerable to a code injection attack.EPSS 0.8%CVE-2026-45558CRITICALRoxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section saveEPSS 0.8%CVE-2024-43693CRITICALDover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command InjectionEPSS 0.8%CVE-2024-45066CRITICALDover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command InjectionEPSS 0.8%CVE-2025-64093CRITICALUnauthenticated Remote Code Execution via the device hostnameEPSS 0.8%CVE-2026-54680CRITICALLogging operator has Fluentd configuration injection that allows remote code executionEPSS 0.8%CVE-2024-7700MEDIUMForeman: command injection in "host init config" template via "install packages" field on foremanEPSS 0.8%