CVE-2022-26376
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
05/08/2022
Last modified:
02/12/2022
Description
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:asus:asuswrt:*:*:*:*:*:*:*:* | 3.0.0.4.386_48706 (excluding) | |
| cpe:2.3:o:asuswrt-merlin:new_gen:*:*:*:*:*:*:*:* | 386.7 (excluding) | |
| cpe:2.3:o:asus:xt8_firmware:*:*:*:*:*:*:*:* | 3.0.0.4.386_48706 (excluding) | |
| cpe:2.3:h:asus:xt8:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:tuf-ax3000_v2_firmware:*:*:*:*:*:*:*:* | 3.0.0.4.386_48750 (excluding) | |
| cpe:2.3:h:asus:tuf-ax3000_v2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:xd4_firmware:*:*:*:*:*:*:*:* | 3.0.0.4.386_48790 (excluding) | |
| cpe:2.3:h:asus:xd4:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:et12_firmware:*:*:*:*:*:*:*:* | 3.0.0.4.386_48823 (excluding) | |
| cpe:2.3:h:asus:et12:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:gt-ax6000_firmware:*:*:*:*:*:*:*:* | 3.0.0.4.386_48823 (excluding) | |
| cpe:2.3:h:asus:gt-ax6000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:xt12_firmware:*:*:*:*:*:*:*:* | 3.0.0.4.386_48823 (excluding) | |
| cpe:2.3:h:asus:xt12:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:asus:rt-ax58u_firmware:*:*:*:*:*:*:*:* | 3.0.0.4.386_48908 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



