Falhas do tipo CWE-77

2.811 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2023-41029HIGHJuplink RX4-1500 Command Injection VulnerabilityEPSS 2.7%CVE-2026-10873HIGHShibby Tomato Web UI rstats rstats_path os command injectionEPSS 2.7%CVE-2026-41304HIGHWWBN AVideo vulnerable to RCE caused by clonesite pluginEPSS 2.7%CVE-2024-7440MEDIUMVivotek CC8160 upload_file.cgi getenv command injectionEPSS 2.7%CVE-2024-7442MEDIUMVivotek SD9364 upload_file.cgi getenv command injectionEPSS 2.7%CVE-2024-7443MEDIUMVivotek IB8367A upload_file.cgi getenv command injectionEPSS 2.7%CVE-2026-0641MEDIUMTOTOLINK WA300 cstecgi.cgi sub_401510 command injectionEPSS 2.7%CVE-2025-14188HIGHUGREEN DH2100+ nas_svr create handler_file_backup_create command injectionEPSS 2.7%CVE-2025-1546MEDIUMBDCOM Behavior Management and Auditing System operate.mds log_operate_clear os command injectionEPSS 2.7%CVE-2026-15495MEDIUMSonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injectionEPSS 2.7%CVE-2026-1150MEDIUMTotolink LR350 POST Request cstecgi.cgi setTracerouteCfg command injectionEPSS 2.7%CVE-2019-5446—Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.EPSS 2.7%CVE-2025-66219MEDIUMwillitmerge has a command Injection vulnerabilityEPSS 2.7%CVE-2019-13552—In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-suppliedEPSS 2.7%CVE-2026-18641MEDIUMSangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injectionEPSS 2.7%CVE-2026-19379MEDIUMEFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionEPSS 2.7%CVE-2026-9367MEDIUMNousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injectionEPSS 2.7%CVE-2026-9834HIGHWP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' ParameterEPSS 2.7%CVE-2026-10872HIGHShibby Tomato Web UI rc start_vpnserver os command injectionEPSS 2.6%CVE-2026-28672CRITICALApache Ranger: OS Command Injection via Username in UnixUserGroupBuilderEPSS 2.6%