Falhas do tipo CWE-77

2.812 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-4849MEDIUMTOTOLINK N300RH cstecgi.cgi CloudACMunualUpdateUserdata command injectionEPSS 1.5%CVE-2023-22763HIGHAuthenticated Remote Command Execution in the ArubaOS Command Line InterfaceEPSS 1.5%CVE-2023-22767HIGHAuthenticated Remote Command Execution in the ArubaOS Command Line InterfaceEPSS 1.5%CVE-2023-22766HIGHAuthenticated Remote Command Execution in the ArubaOS Command Line InterfaceEPSS 1.5%CVE-2023-22765HIGHAuthenticated Remote Command Execution in the ArubaOS Command Line InterfaceEPSS 1.5%CVE-2023-22764HIGHAuthenticated Remote Command Execution in the ArubaOS Command Line InterfaceEPSS 1.5%CVE-2025-66404MEDIUMmcp-server-kubernetes potential security issue in exec_in_pod toolEPSS 1.5%CVE-2026-21520HIGHCopilot Studio Information Disclosure VulnerabilityEPSS 1.5%CVE-2024-37385CRITICALRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: thEPSS 1.5%CVE-2022-21191HIGHVersions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checEPSS 1.5%CVE-2025-60675MEDIUMA command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconEPSS 1.5%CVE-2025-2916MEDIUMAishida Call Center System amr2mp3 command injectionEPSS 1.5%CVE-2024-25998HIGHPHOENIX CONTACT: Command injection in the OCPP ServiceEPSS 1.5%CVE-2024-57536HIGHLinksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.EPSS 1.5%CVE-2024-48860CRITICALQHoraEPSS 1.5%CVE-2026-92993MEDIUMDromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injectionEPSS 1.5%CVE-2026-26461MEDIUMA Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to executEPSS 1.5%CVE-2024-44382HIGHD-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.EPSS 1.5%CVE-2024-25255CRITICALSublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties repEPSS 1.5%CVE-2025-60682MEDIUMA command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, sEPSS 1.5%