Falhas do tipo CWE-77

2.819 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2021-41144HIGHOpenMage LTS authenticated remote code execution through layout updateEPSS 1.2%CVE-2025-4747MEDIUMBohua NetDragon Firewall ip_status.php command injectionEPSS 1.2%CVE-2024-0817CRITICALCommand injection in IrGraph.draw in paddlepaddle/paddle 2.6.0EPSS 1.2%CVE-2024-27981CRITICALA Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and eaEPSS 1.2%CVE-2026-94139MEDIUMChengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injectionEPSS 1.2%CVE-2026-97366MEDIUMjhen0409 react-native-debugger Open in Editor window.js openDevTools os command injectionEPSS 1.2%CVE-2025-24285CRITICALMultiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with EPSS 1.2%CVE-2024-57229MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the resEPSS 1.1%CVE-2024-57231MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apclEPSS 1.1%CVE-2024-57230MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apclEPSS 1.1%CVE-2024-57232MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apclEPSS 1.1%CVE-2024-57235MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_eEPSS 1.1%CVE-2024-57234MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apclEPSS 1.1%CVE-2024-57233MEDIUMNETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_dEPSS 1.1%CVE-2024-55461CRITICALSeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().EPSS 1.1%CVE-2025-59046CRITICALinteractive-git-checkout has Command Injection vulnerabilityEPSS 1.1%CVE-2026-21256HIGHGitHub Copilot and Visual Studio Remote Code Execution VulnerabilityEPSS 1.1%CVE-2024-30167MEDIUM/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a PEPSS 1.1%CVE-2024-20432CRITICALCisco Nexus Dashboard Fabric Controller Web UI Command Injection VulnerabilityEPSS 1.1%CVE-2023-1168HIGHAuthenticated Remote Code Execution in Aruba CX SwitchesEPSS 1.1%