Falhas do tipo CWE-77

2.810 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2020-3275HIGHCisco Small Business RV Series Routers Command Injection VulnerabilitiesEPSS 2.8%CVE-2020-3279HIGHCisco Small Business RV Series Routers Command Injection VulnerabilitiesEPSS 2.8%CVE-2020-3276HIGHCisco Small Business RV Series Routers Command Injection VulnerabilitiesEPSS 2.8%CVE-2020-3277HIGHCisco Small Business RV Series Routers Command Injection VulnerabilitiesEPSS 2.8%CVE-2020-3278HIGHCisco Small Business RV Series Routers Command Injection VulnerabilitiesEPSS 2.8%CVE-2020-3274HIGHCisco Small Business RV Series Routers Command Injection VulnerabilitiesEPSS 2.8%CVE-2022-42161HIGHD-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at functioEPSS 2.8%CVE-2022-42156HIGHD-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at functionEPSS 2.8%CVE-2026-34243CRITICALwenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`EPSS 2.8%CVE-2020-8186—A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input toEPSS 2.8%CVE-2022-21129HIGHVersions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exporEPSS 2.8%CVE-2024-2642HIGHRuijie RG-NBS2009G-P EXCU_SHELL command injectionEPSS 2.8%CVE-2024-35374CRITICALMocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to EPSS 2.8%CVE-2025-5525MEDIUMJrohy trojan linux.go LogChan os command injectionEPSS 2.8%CVE-2025-3249MEDIUMTOTOLINK A6000R mtkwifi.lua apcli_cancel_wps command injectionEPSS 2.8%CVE-2018-3772—Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary commands. The `whereis` moEPSS 2.8%CVE-2025-14586MEDIUMTOTOLINK X5000R cstecgi.cgi snprintf os command injectionEPSS 2.8%CVE-2022-42160HIGHD-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at functEPSS 2.8%CVE-2026-38713CRITICALTR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2EPSS 2.8%CVE-2026-38708CRITICALTR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2EPSS 2.8%