Vulnerability Description
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asus | Asuswrt | < 3.0.0.4.386_48706 |
| Asuswrt-Merlin | New Gen | < 386.7 |
| Asus | Xt8 Firmware | < 3.0.0.4.386_48706 |
| Asus | Xt8 | - |
| Asus | Tuf-Ax3000 V2 Firmware | < 3.0.0.4.386_48750 |
| Asus | Tuf-Ax3000 V2 | - |
| Asus | Xd4 Firmware | < 3.0.0.4.386_48790 |
| Asus | Xd4 | - |
| Asus | Et12 Firmware | < 3.0.0.4.386_48823 |
| Asus | Et12 | - |
| Asus | Gt-Ax6000 Firmware | < 3.0.0.4.386_48823 |
| Asus | Gt-Ax6000 | - |
| Asus | Xt12 Firmware | < 3.0.0.4.386_48823 |
| Asus | Xt12 | - |
| Asus | Rt-Ax58U Firmware | < 3.0.0.4.386_48908 |
| Asus | Rt-Ax58U | - |
| Asus | Xt9 Firmware | < 3.0.0.4.388_20027 |
| Asus | Xt9 | - |
| Asus | Xd6 Firmware | < 3.0.0.4.386_49356 |
| Asus | Xd6 | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1511ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1511ExploitThird Party Advisory
FAQ
What is CVE-2022-26376?
CVE-2022-26376 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead...
How severe is CVE-2022-26376?
CVE-2022-26376 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-26376?
Check the references section above for vendor advisories and patch information. Affected products include: Asus Asuswrt, Asuswrt-Merlin New Gen, Asus Xt8 Firmware, Asus Xt8, Asus Tuf-Ax3000 V2 Firmware.