Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-31173MEDIUMAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the intervaEPSS 0.7%CVE-2026-31172MEDIUMAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user paEPSS 0.7%CVE-2026-31174MEDIUMAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEEPSS 0.7%CVE-2026-73751HIGHAuthenticated Remote Command Injection in AOS-CX Web-based Management InterfaceEPSS 0.7%CVE-2026-49196HIGHPredator Connect W6x: Web Interface Command InjectionEPSS 0.7%CVE-2026-52199CRITICALAn issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd componentEPSS 0.7%CVE-2025-29227MEDIUMIn Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function EPSS 0.7%CVE-2024-2366CRITICALRemote Code Execution in parisneo/lollms-webuiEPSS 0.7%CVE-2026-35847CRITICALAn issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php fileEPSS 0.7%CVE-2018-0324—A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attaEPSS 0.7%CVE-2025-37138MEDIUMAuthenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required)EPSS 0.7%CVE-2024-7840HIGHImproper neutralization special element in hyperlinksEPSS 0.7%CVE-2025-65946HIGHRoo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation BugEPSS 0.7%CVE-2026-12045CRITICALpgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code executionEPSS 0.7%CVE-2025-29226MEDIUMIn Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function EPSS 0.7%CVE-2025-29223MEDIUMLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.EPSS 0.7%CVE-2020-14342MEDIUMIt was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary coEPSS 0.7%CVE-2026-72869CRITICALDokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEEPSS 0.7%CVE-2025-12107HIGHServer-Side Template Injection via Velocity Template Engine in Multiple WSO2 Products Allows Remote Code ExecutionEPSS 0.6%CVE-2026-24299MEDIUMM365 Copilot Information Disclosure VulnerabilityEPSS 0.6%