Falhas do tipo CWE-77

2.816 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-43844HIGHGHSL-2025-014_Retrieval-based-Voice-Conversion-WebUIEPSS 2.1%CVE-2025-43842HIGHGHSL-2025-012_Retrieval-based-Voice-Conversion-WebUIEPSS 2.1%CVE-2025-5106MEDIUMFujian Kelixun Filename fax_view.php os command injectionEPSS 2.1%CVE-2025-6103HIGHWifi-soft UniBox Controller test_accesscodelogin.php os command injectionEPSS 2.1%CVE-2018-19950—If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP SystEPSS 2.1%CVE-2026-7590MEDIUMeyal-gor p_69_branch_monkey_mcp Preview Endpoint advanced.py os command injectionEPSS 2.1%CVE-2026-7785MEDIUMA-G-U-P-T-A wireshark-mcp pyshark_mcp.py quick_capture os command injectionEPSS 2.1%CVE-2026-7064MEDIUMAgentDeskAI browser-tools-mcp browser-connector.ts os command injectionEPSS 2.1%CVE-2026-5690MEDIUMTotolink A7100RU cstecgi.cgi setRemoteCfg os command injectionEPSS 2.1%CVE-2026-5692MEDIUMTotolink A7100RU cstecgi.cgi setGameSpeedCfg os command injectionEPSS 2.1%CVE-2026-7215MEDIUMegtai gmx-vmd-mcp VMD Launch mcp_server.py launch_vmd_gui_tool command injectionEPSS 2.1%CVE-2026-90619MEDIUM0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injectionEPSS 2.1%CVE-2026-5689MEDIUMTotolink A7100RU cstecgi.cgi setNtpCfg os command injectionEPSS 2.1%CVE-2026-7812MEDIUM54yyyu code-mcp MCP Tool server.py git_operation command injectionEPSS 2.1%CVE-2026-7211MEDIUMdvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injectionEPSS 2.1%CVE-2026-6158MEDIUMTotolink N300RH upgrade.so setUpgradeUboot os command injectionEPSS 2.1%CVE-2026-5677MEDIUMTotolink A7100RU cstecgi.cgi CsteSystem os command injectionEPSS 2.1%CVE-2026-5741MEDIUMsuvarchal docker-mcp-server HTTP index.ts pull_image os command injectionEPSS 2.1%CVE-2026-7220MEDIUMjackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injectionEPSS 2.1%CVE-2026-19983MEDIUMGL.iNet XE3000 NAS Command Service gl_nas_sys os command injectionEPSS 2.1%