Description
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Published: 2022-08-05
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-30935 A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
History

Tue, 15 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Asus Asuswrt Et12 Et12 Firmware Gt-ax11000 Gt-ax11000 Firmware Gt-ax11000 Pro Gt-ax11000 Pro Firmware Gt-ax6000 Gt-ax6000 Firmware Gt-axe16000 Gt-axe16000 Firmware Rt-ax55 Rt-ax55 Firmware Rt-ax56u Rt-ax56u Firmware Rt-ax58u Rt-ax58u Firmware Rt-ax68u Rt-ax68u Firmware Rt-ax82u Rt-ax82u Firmware Rt-ax86u Rt-ax86u Firmware Tuf-ax3000 V2 Tuf-ax3000 V2 Firmware Xd4 Xd4 Firmware Xd6 Xd6 Firmware Xt12 Xt12 Firmware Xt8 Xt8 Firmware Xt9 Xt9 Firmware
Asuswrt-merlin New Gen
cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2025-04-15T18:53:55.243Z

Reserved: 2022-04-05T00:00:00.000Z

Link: CVE-2022-26376

cve-icon Vulnrichment

Updated: 2024-08-03T05:03:32.976Z

cve-icon NVD

Status : Modified

Published: 2022-08-05T22:15:11.143

Modified: 2024-11-21T06:53:52.570

Link: CVE-2022-26376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses