Falhas do tipo CWE-77

2.819 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2023-27848CRITICALbroccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.EPSS 1.9%CVE-2023-35932HIGHjcvi vulnerable to Configuration Injection due to unsanitized user input EPSS 1.9%CVE-2023-46416HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 funcEPSS 1.9%CVE-2023-46424HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.EPSS 1.9%CVE-2023-46422HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.EPSS 1.9%CVE-2023-46414HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 functionEPSS 1.9%CVE-2023-46417HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.EPSS 1.9%CVE-2023-46421HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.EPSS 1.9%CVE-2023-46423HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.EPSS 1.9%CVE-2023-46415HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.EPSS 1.9%CVE-2023-46420HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.EPSS 1.9%CVE-2023-46418HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.EPSS 1.9%CVE-2023-46419HIGHTOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.EPSS 1.9%CVE-2023-4310—BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability whicEPSS 1.8%CVE-2025-45489MEDIUMLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostnaEPSS 1.8%CVE-2022-40752CRITICALIBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-FEPSS 1.8%CVE-2025-50757MEDIUMWavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. ThisEPSS 1.8%CVE-2023-34233HIGHSnowflake Python Connector vulnerable to Command InjectionEPSS 1.8%CVE-2024-11634CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authentiEPSS 1.8%CVE-2021-3855HIGHCommand Injection in Liman Central Management SystemEPSS 1.8%