Falhas do tipo CWE-77

2.834 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2019-1613MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1613)EPSS 0.4%CVE-2021-43589MEDIUMDell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection VEPSS 0.4%CVE-2026-76321HIGHSPL Injection through Nearby Event Searches in Splunk EnterpriseEPSS 0.4%CVE-2023-22657HIGHF5OS vulnerabilityEPSS 0.4%CVE-2025-71392CRITICALSurrealDB before 2.2.2 SurrealQL Injection via exportEPSS 0.4%CVE-2024-4638HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via webUploadKeyEPSS 0.4%CVE-2024-57685MEDIUMAn issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.EPSS 0.4%CVE-2026-23862HIGHDell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command InjEPSS 0.4%CVE-2025-44023MEDIUMAn issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account_mgr.cgi->cgi_chg_adEPSS 0.4%CVE-2026-54090HIGHFile Browser: Command Allowlist Bypass via Shell Metacharacter InjectionEPSS 0.4%CVE-2025-52483HIGHRegistrator.jl Vulnerable to Argument Injection and Command InjectionEPSS 0.4%CVE-2024-56836HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEEPSS 0.4%CVE-2026-35070MEDIUMDell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('CommEPSS 0.4%CVE-2026-21522MEDIUMMicrosoft ACI Confidential Containers Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-29155MEDIUMAn issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpointEPSS 0.4%CVE-2024-48141HIGHA prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsEPSS 0.4%CVE-2025-48979LOWAn Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileges and local access.EPSS 0.4%CVE-2024-51254HIGHDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.4%CVE-2024-51736NONECommand execution hijack on Windows with Process class in symfony/processEPSS 0.4%CVE-2025-15366MEDIUMIMAP command injection in user-controlled commandsEPSS 0.4%