Falhas do tipo CWE-77

2.816 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-59738CRITICALMultiple vulnerabilities in AndSoft's e-TMSEPSS 1.4%CVE-2025-59736CRITICALMultiple vulnerabilities in AndSoft's e-TMSEPSS 1.4%CVE-2025-59739CRITICALMultiple vulnerabilities in AndSoft's e-TMSEPSS 1.4%CVE-2024-44381HIGHD-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.EPSS 1.4%CVE-2024-57539HIGHLinksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.EPSS 1.4%CVE-2023-49959CRITICALIn Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote EPSS 1.4%CVE-2026-10273MEDIUMphp-censor Webhook Endpoint GitBuild.php os command injectionEPSS 1.4%CVE-2022-27588CRITICALVulnerability in QVREPSS 1.4%CVE-2025-29522MEDIUMD-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.EPSS 1.4%CVE-2023-0636HIGHRemote Code Execution via Command InjectionEPSS 1.4%CVE-2024-20667HIGHAzure DevOps Server Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-39570HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to commaEPSS 1.4%CVE-2026-93371MEDIUMmarcopiovanello yt-dlp-web-ui generic.go NewGenericDownload command injectionEPSS 1.4%CVE-2023-23952CRITICALAdvanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.EPSS 1.4%CVE-2024-39563MEDIUMJunos Space: Remote Command Execution (RCE) vulnerability in web applicationEPSS 1.3%CVE-2019-11278HIGHPrivilege Escalation via Blind SCIM Injection in UAAEPSS 1.3%CVE-2020-8188—We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine PEPSS 1.3%CVE-2025-55227HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2023-31729CRITICALTOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.EPSS 1.3%CVE-2026-10214MEDIUMzhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injectionEPSS 1.3%