CVE-2022-26376

CVSS V2 None CVSS V3 Critical 9.8
Description
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Overview
  • CVE ID
  • CVE-2022-26376
  • Assigner
  • talos-cna@cisco.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-08-05T22:15:11
  • Last Modified Date
  • 2022-12-02T20:08:05
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:asus:asuswrt:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48706
AND
cpe:2.3:o:asuswrt-merlin:new_gen:*:*:*:*:*:*:*:* 1 OR 386.7
AND
cpe:2.3:o:asus:xt8_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48706
cpe:2.3:h:asus:xt8:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:tuf-ax3000_v2_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48750
cpe:2.3:h:asus:tuf-ax3000_v2:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:xd4_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48790
cpe:2.3:h:asus:xd4:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:et12_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48823
cpe:2.3:h:asus:et12:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:gt-ax6000_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48823
cpe:2.3:h:asus:gt-ax6000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:xt12_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48823
cpe:2.3:h:asus:xt12:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:rt-ax58u_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48908
cpe:2.3:h:asus:rt-ax58u:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:xt9_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.388_20027
cpe:2.3:h:asus:xt9:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:xd6_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_49356
cpe:2.3:h:asus:xd6:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:gt-ax11000_pro_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48996
cpe:2.3:h:asus:gt-ax11000_pro:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:gt-axe16000_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_48786
cpe:2.3:h:asus:gt-axe16000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:rt-ax86u_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_49447
cpe:2.3:h:asus:rt-ax86u:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:rt-ax68u_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_49479
cpe:2.3:h:asus:rt-ax68u:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:rt-ax82u_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_49380
cpe:2.3:h:asus:rt-ax82u:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:rt-ax56u_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_49559
cpe:2.3:h:asus:rt-ax56u:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:rt-ax55_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_49559
cpe:2.3:h:asus:rt-ax55:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:asus:gt-ax11000_firmware:*:*:*:*:*:*:*:* 1 OR 3.0.0.4.386_49559
cpe:2.3:h:asus:gt-ax11000:-:*:*:*:*:*:*:* 0 OR
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 9.8
  • Base Severity
  • CRITICAL
  • Exploitability Score
  • 3.9
  • Impact Score
  • 5.9
History
Created Old Value New Value Data Type Notes
2022-08-05 23:00:09 Added to TrackCVE
2022-12-06 14:34:07 2022-12-02T20:08:05 CVE Modified Date updated
2022-12-06 14:34:07 Undergoing Analysis Analyzed Vulnerability Status updated