Falhas do tipo CWE-77

2.816 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-44872HIGHAuthenticated Arbitrary File Upload via Command Injection in AOS-8 AND AOS-10 Web-Based Management InterfaceEPSS 1.2%CVE-2025-56799MEDIUMReolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted foldeEPSS 1.2%CVE-2020-8101MEDIUMCommand execution due to unsanitized input in LifeShield DIY HD Video DoorbellEPSS 1.2%CVE-2022-25350HIGHAll versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization. EPSS 1.2%CVE-2023-6940CRITICALCommand InjectionEPSS 1.2%CVE-2022-21810HIGHAll versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization. EPSS 1.2%CVE-2023-27224CRITICALAn issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.EPSS 1.2%CVE-2021-32933CRITICALMDT AutoSave Command InjectionEPSS 1.2%CVE-2025-45798MEDIUMA command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg inEPSS 1.2%CVE-2026-54501CRITICALBrowsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom BehaviorsEPSS 1.2%CVE-2022-41617HIGHBIG-IP Advanced WAF and ASM iControl REST vulnerability CVE-2022-41617EPSS 1.2%CVE-2024-39373CRITICALImproper Neutralization of Special Elements used in a Command in TELSAT marKoni FM TransmitterEPSS 1.2%CVE-2021-32661MEDIUMTechDocs object element script injectionEPSS 1.2%CVE-2023-30353CRITICALShenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.EPSS 1.2%CVE-2024-38894MEDIUMWAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.EPSS 1.2%CVE-2025-52903HIGHFile Browser Allows Execution of Shell Commands That Can Spawn Other CommandsEPSS 1.2%CVE-2025-27212CRITICALAn Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi AccesEPSS 1.2%CVE-2025-53104CRITICALgluestack-ui Command Injection Vulnerability via discussion-to-slack GitHub Action WorkflowEPSS 1.2%CVE-2025-60854CRITICALA vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change rEPSS 1.2%CVE-2024-53700MEDIUMQHoraEPSS 1.2%