Falhas do tipo CWE-77

2.816 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2020-27867MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R62EPSS 2.2%CVE-2023-41031HIGHJuplink RX4-1500 homemng.htm Command Injection VulnerabilityEPSS 2.2%CVE-2024-46662HIGHA improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3,EPSS 2.2%CVE-2025-43843HIGHGHSL-2025-013_Retrieval-based-Voice-Conversion-WebUIEPSS 2.2%CVE-2024-0579MEDIUMTotolink X2000R formMapDelDevice command injectionEPSS 2.2%CVE-2021-41599—Improper control flow in GitHub Enterprise Server hosted Pages leads to remote code executionEPSS 2.2%CVE-2026-15035MEDIUMbentoml OpenLLM Model Repository Directory Name common.py async_run_command command injectionEPSS 2.2%CVE-2025-0328MEDIUMKaiYuanTong ECT Platform HTTP POST Request runCode.php command injectionEPSS 2.2%CVE-2024-28354CRITICALThere is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands EPSS 2.2%CVE-2023-42810CRITICALsysteminformation SSID Command Injection VulnerabilityEPSS 2.2%CVE-2025-14184MEDIUMSGAI Space1 NAS N1211DS gsaiagent JSONAPI NGNIX_UPLOAD command injectionEPSS 2.2%CVE-2024-45505HIGHApache HertzBeat: Exists Native Deser RCE and file writing vulnerabilitiesEPSS 2.2%CVE-2023-31531HIGHMotorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.EPSS 2.2%CVE-2023-31529HIGHMotorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.EPSS 2.2%CVE-2023-31528HIGHMotorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter.EPSS 2.2%CVE-2020-2490HIGHIf exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP SysteEPSS 2.2%CVE-2021-4329MEDIUMjson-logic-js logic.js command injectionEPSS 2.2%CVE-2026-5532MEDIUMScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_execute os command injectionEPSS 2.2%CVE-2026-1601MEDIUMTotolink A7000R cstecgi.cgi setUploadUserData command injectionEPSS 2.2%CVE-2026-10870HIGHShibby Tomato Web UI rc start_dhcpc os command injectionEPSS 2.2%