Falhas do tipo CWE-77

2.816 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2023-33530HIGHThere is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web EPSS 1.3%CVE-2025-9174MEDIUMneurobin shc Filename shc.c make os command injectionEPSS 1.3%CVE-2025-12155HIGHCommand Injection in LookerEPSS 1.3%CVE-2021-41143HIGHOpenMage LTS arbitrary file deletion in customer media allows for remote code executionEPSS 1.3%CVE-2023-22913HIGHA post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4EPSS 1.3%CVE-2025-9176MEDIUMneurobin shc Environment Variable shc.c make os command injectionEPSS 1.3%CVE-2022-41870HIGHAP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.EPSS 1.3%CVE-2024-33508MEDIUMAn improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2EPSS 1.3%CVE-2025-51457HIGHD-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoEPSS 1.3%CVE-2024-48017MEDIUMDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 1.3%CVE-2024-45824CRITICALFactoryTalk® View Site Edition Remote Code Execution Vulnerability via Lack of Input ValidationEPSS 1.3%CVE-2023-24330HIGHCommand Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via craEPSS 1.3%CVE-2023-6999HIGHPods - Custom Content Types and Fields - Authenticated (Contributor+) Remote Code ExecutionEPSS 1.3%CVE-2023-7227CRITICALCommand Injection vulnerability in SystemK NVR 504/508/516EPSS 1.3%CVE-2023-24612CRITICALThe PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.EPSS 1.3%CVE-2024-24216CRITICALZentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/mEPSS 1.3%CVE-2025-29229CRITICALlinksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.EPSS 1.3%CVE-2025-29228CRITICALLinksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.EPSS 1.3%CVE-2025-26063CRITICALAn issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted paEPSS 1.3%CVE-2021-32660MEDIUMTechDocs content sanitization bypassEPSS 1.3%