Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-7575HIGHImproper neutralization special element in hyperlinksEPSS 0.7%CVE-2023-47356HIGHMingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameterEPSS 0.7%CVE-2017-12339—A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attackEPSS 0.7%CVE-2025-22473HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.7%CVE-2024-49194HIGHDatabricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL pEPSS 0.7%CVE-2024-49557HIGHDell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.7%CVE-2026-35580CRITICALEmissary has GitHub Actions Shell Injection via Workflow InputsEPSS 0.7%CVE-2024-24550HIGHBludit - Remote Code Execution (RCE) through File APIEPSS 0.7%CVE-2025-45619MEDIUMAn issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction functionEPSS 0.7%CVE-2023-50274HIGHHPE OneView may allow command injection with local privilege escalation.EPSS 0.7%CVE-2024-57213MEDIUMTOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_EPSS 0.7%CVE-2024-57214MEDIUMTOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifEPSS 0.7%CVE-2025-46816CRITICALgoshs route not protected, allows command executionEPSS 0.7%CVE-2025-66032HIGHClaude Code Command Validation Bypass Allows Arbitrary Code ExecutionEPSS 0.7%CVE-2025-67728CRITICALFireshare Public Uploads feature is vulnerable to OS Command Injection (RCE)EPSS 0.7%CVE-2023-4401HIGH Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. AEPSS 0.7%CVE-2024-43497HIGHDeepSpeed Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-22864HIGHDeno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypassEPSS 0.7%CVE-2024-41134HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.7%CVE-2017-12341—A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attackEPSS 0.7%