CVE-2022-26376 is a critical memory corruption vulnerability in the httpd unescape functionality of Asuswrt and Asuswrt-Merlin New Gen firmware, affecting versions prior to 3.0.0.4.386_48706 and 386.7 respectively. This flaw allows an unauthenticated attacker to execute arbitrary code or cause a denial of service by sending a specially crafted HTTP request over the network. With a CVSS score of 9.8 (CRITICAL), it presents a high risk of complete compromise of confidentiality, integrity, and availability. While there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.0.4.386_48706CPE matchmatch criteria | cpe:2.3:o:asus:asuswrt:*:*:*:*:*:*:*:* | ||
< 386.7CPE matchmatch criteria | cpe:2.3:o:asuswrt-merlin:new_gen:*:*:*:*:*:*:*:* | ||
< 3.0.0.4.386_48706CPE matchmatch criteria | cpe:2.3:o:asus:xt8_firmware:*:*:*:*:*:*:*:* | ||
< 3.0.0.4.386_48750CPE matchmatch criteria | cpe:2.3:o:asus:tuf-ax3000_v2_firmware:*:*:*:*:*:*:*:* | ||
< 3.0.0.4.386_48790CPE matchmatch criteria | cpe:2.3:o:asus:xd4_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.