Falhas do tipo CWE-77

2.813 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2023-27837CRITICALTP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the functiEPSS 2.4%CVE-2019-15575—A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API throughEPSS 2.4%CVE-2024-29366HIGHA command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.EPSS 2.4%CVE-2026-2167MEDIUMTotolink WA300 cstecgi.cgi setAPNetwork os command injectionEPSS 2.4%CVE-2026-77988MEDIUMTRENDnet TEW-823DRU CLI Configuration Tool nvram_get command injectionEPSS 2.4%CVE-2025-57200MEDIUMAVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iEPSS 2.4%CVE-2023-31530HIGHMotorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.EPSS 2.4%CVE-2026-12197HIGHRuijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injectionEPSS 2.4%CVE-2026-94098CRITICALNetcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injectionEPSS 2.4%CVE-2019-25029—In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via EPSS 2.4%CVE-2024-33789CRITICALLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.EPSS 2.4%CVE-2025-7614MEDIUMTOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injectionEPSS 2.4%CVE-2025-7615MEDIUMTOTOLINK T6 HTTP POST Request cstecgi.cgi clearPairCfg command injectionEPSS 2.4%CVE-2025-69256HIGHserverless MCP Server vulnerable to command injection in list-projects toolEPSS 2.4%CVE-2025-7613MEDIUMTOTOLINK T6 HTTP POST Request cstecgi.cgi CloudSrvVersionCheck command injectionEPSS 2.4%CVE-2017-12078HIGHCommand injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execuEPSS 2.4%CVE-2026-9296MEDIUMEdimax BR-6428NS POST Request formWlanM system command injectionEPSS 2.4%CVE-2026-6799MEDIUMComfast CF-N1-S Endpoint mbox-config command injectionEPSS 2.4%CVE-2026-8753MEDIUMkalcaddle Kodbox fileThumb Plugin VideoResize.class.php parseVideoInfo command injectionEPSS 2.4%CVE-2026-7682MEDIUMEdimax BR-6208AC L2TP Mode setWAN command injectionEPSS 2.4%