Falhas do tipo CWE-77

2.810 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-56706HIGHEdimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getCoEPSS 2.0%CVE-2024-36604CRITICALTenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerabilitEPSS 2.0%CVE-2024-42509CRITICALUnauthenticated Command Injection Vulnerability in the CLI Service Accessed by the PAPI ProtocolEPSS 2.0%CVE-2026-12186HIGHGL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injectionEPSS 2.0%CVE-2026-22688CRITICALWeKnora has Command Injection in MCP stdio testEPSS 2.0%CVE-2023-34231HIGHSnowflake Golang Driver vulnerable to Command InjectionEPSS 2.0%CVE-2023-33556CRITICALTOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/seEPSS 2.0%CVE-2024-44845HIGHDrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_EPSS 2.0%CVE-2025-15607HIGHAuthenticated Command Injection in mcsd Service of TP-Link Archer AX53EPSS 2.0%CVE-2025-50756CRITICALWavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This EPSS 1.9%CVE-2024-33788HIGHLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.EPSS 1.9%CVE-2023-24144CRITICALTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg funcEPSS 1.9%CVE-2023-24142CRITICALTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkEPSS 1.9%CVE-2023-24143CRITICALTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetwoEPSS 1.9%CVE-2023-24154CRITICALTOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.EPSS 1.9%CVE-2023-24141CRITICALTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetwEPSS 1.9%CVE-2023-24140CRITICALTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDEPSS 1.9%CVE-2023-24139CRITICALTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiagEPSS 1.9%CVE-2026-12187HIGHGL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injectionEPSS 1.9%CVE-2017-12075HIGHCommand injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to eEPSS 1.9%