Falhas do tipo CWE-77

2.816 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-5802MEDIUMidachev mcp-javadc HTTP os command injectionEPSS 2.1%CVE-2026-79912MEDIUMTOTOLINK N600R cstecgi.cgi getCurrentTime command injectionEPSS 2.1%CVE-2023-24152CRITICALA command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execEPSS 2.1%CVE-2023-24157CRITICALA command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execuEPSS 2.1%CVE-2026-14802MEDIUMreact create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injectionEPSS 2.1%CVE-2026-25761HIGHCommand injection via crafted filenames in Super-linter ActionEPSS 2.1%CVE-2021-22935—A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitEPSS 2.1%CVE-2021-22938—A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitEPSS 2.1%CVE-2020-36642MEDIUMtrampgeek jobe LanguageTask.php run_in_sandbox command injectionEPSS 2.1%CVE-2025-29523HIGHD-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 functionEPSS 2.1%CVE-2024-24301HIGHCommand Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with vaEPSS 2.1%CVE-2026-94490MEDIUMOctoPrint Command API system.py executeSystemCommand os command injectionEPSS 2.1%CVE-2024-32353CRITICALTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSSerEPSS 2.1%CVE-2025-64424CRITICALColify has command injection vulnerability in project git sourceEPSS 2.1%CVE-2020-36650MEDIUMIonicaBizau node-gry command injectionEPSS 2.1%CVE-2025-61787HIGHDeno is Vulnerable to Command Injection on Windows During Batch File ExecutionEPSS 2.1%CVE-2022-21941CRITICALiSTAR UltraEPSS 2.1%CVE-2023-24150CRITICALA command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to executEPSS 2.1%CVE-2023-35390HIGH.NET and Visual Studio Remote Code Execution VulnerabilityEPSS 2.1%CVE-2023-24135HIGHJensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMEPSS 2.1%