Falhas do tipo CWE-77

2.810 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-15033MEDIUMchristopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injectionEPSS 1.8%CVE-2026-82597MEDIUMTOTOLINK NR1800X cstecgi.cgi setUssd command injectionEPSS 1.8%CVE-2026-4192MEDIUMAvinashBole quip-mcp-server index.ts setupToolHandlers command injectionEPSS 1.8%CVE-2026-6141MEDIUMdanielmiessler Personal_AI_Infrastructure parse_url.ts os command injectionEPSS 1.8%CVE-2026-15513MEDIUMWavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injectionEPSS 1.8%CVE-2026-75011MEDIUMkylecui NetForensicMCP index.js execAsync command injectionEPSS 1.8%CVE-2026-75985MEDIUMTRENDnet Router ping.cgi command injectionEPSS 1.8%CVE-2026-90621MEDIUMipa-lab HackingBuddyGPT ssh_run_command.py ssh_run_command os command injectionEPSS 1.8%CVE-2026-91853MEDIUMTOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injectionEPSS 1.8%CVE-2025-58132MEDIUMZoom Clients for Windows - Command InjectionEPSS 1.8%CVE-2025-44877CRITICALTenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parametEPSS 1.8%CVE-2025-44872CRITICALTenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName paraEPSS 1.8%CVE-2020-3224HIGHCisco IOS XE Software Web UI Command Injection VulnerabilityEPSS 1.8%CVE-2025-14485LOWEFM ipTIME A3004T Administrator Password timepro.cgi show_debug_screen command injectionEPSS 1.8%CVE-2024-32281HIGHTenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.EPSS 1.8%CVE-2023-1277HIGHkylin-system-updater Update InstallSnap command injectionEPSS 1.8%CVE-2023-1877MEDIUMCommand Injection in microweber/microweberEPSS 1.8%CVE-2023-24145CRITICALTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUsEPSS 1.8%CVE-2023-24148CRITICALTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserDataEPSS 1.8%CVE-2024-55030CRITICALA command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.EPSS 1.8%