Falhas do tipo CWE-77

2.811 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2023-46979CRITICALTOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfgEPSS 1.5%CVE-2023-46976CRITICALTOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.EPSS 1.5%CVE-2023-46993CRITICALIn TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which canEPSS 1.5%CVE-2022-35518MEDIUMWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command iEPSS 1.5%CVE-2024-57583CRITICALTenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf functiEPSS 1.5%CVE-2024-22546MEDIUMTRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privEPSS 1.5%CVE-2025-59735CRITICALMultiple vulnerabilities in AndSoft's e-TMSEPSS 1.5%CVE-2025-26385CRITICALMetasys product command injection vulnerability could allow remote SQL executionEPSS 1.5%CVE-2021-41146HIGHArbitrary command execution on Windows in qutebrowserEPSS 1.5%CVE-2023-39809CRITICALN.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the systemEPSS 1.5%CVE-2026-16488LOWQUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injectionEPSS 1.5%CVE-2024-42505CRITICALUnauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI ProtocolEPSS 1.5%CVE-2026-31255MEDIUMA command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interfaceEPSS 1.5%CVE-2025-4678HIGHRemote Code Execution leads to Command InjectionEPSS 1.5%CVE-2018-19015—An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a EPSS 1.5%CVE-2024-30572HIGHNetgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.EPSS 1.5%CVE-2024-4267HIGHRemote Code Execution in parisneo/lollms-webuiEPSS 1.5%CVE-2023-40301CRITICALNETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.EPSS 1.5%CVE-2025-2733MEDIUMmannaandpoem OpenManus Prompt python_execute.py os command injectionEPSS 1.5%CVE-2023-22765HIGHAuthenticated Remote Command Execution in the ArubaOS Command Line InterfaceEPSS 1.5%