Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Busybox

First CVE: Apr 4, 2006Active for: 20 yearsTotal CVEs: 47
45.5
VTI Score
High

Busybox is a lightweight, single-product utility suite widely embedded in embedded systems, IoT devices, and Linux distributions where space and resource constraints demand minimal footprints. Despite its narrow product scope, the vendor sits deep in the embedded and mobile supply chain, making its vulnerabilities relevant across thousands of downstream deployments. The recurring vulnerability classes—use-after-free, NULL-pointer dereferences, out-of-bounds reads, improper input validation, and path-traversal flaws—reflect the C-based implementation and the parsing complexity inherent to a compact multipurpose utility toolkit. A meaningful share of Busybox's disclosures reach serious severity, and defenders should treat updates to this component as a supply-chain priority given its pervasive embedding in firmware and containerized environments. Current exploitation activity and severity breakdowns are shown alongside this summary.

FAUCET AI Generated
47
Total CVEs
More Total CVEs than 98% of tracked vendors
3.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Busybox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2006
20 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1000517CRITICAL
BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffe
Jun 26, 20189.845NONO
CVE-2016-2148CRITICAL
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
Feb 9, 20179.845NONO
CVE-2026-38755HIGH
A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Jul 15, 20267.534NONO
CVE-2026-38752HIGH
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Jul 15, 20267.533NONO
CVE-2026-38754HIGH
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Jul 15, 20267.533NONO
CVE-2026-38753HIGH
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Jul 15, 20267.532NONO
CVE-2021-42377CRITICAL
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishan
Nov 15, 20219.831NONO
CVE-2017-16544HIGH
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitiz
Nov 20, 20178.831NONO
CVE-2022-48174CRITICAL
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitra
Aug 22, 20239.830NONO
CVE-2022-28391HIGH
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attack
Apr 3, 20228.829NONO
View all 47 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products47 CVEs
32%
55%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (36.2%)
Network27 (57.4%)
Unknown2 (4.3%)
Physical0 (0.0%)
Adjacent Network1 (2.1%)
Attack Complexity
Low42 (89.4%)
High3 (6.4%)
Unknown2 (4.3%)
User Interaction
None34 (72.3%)
Unknown2 (4.3%)
Required11 (23.4%)
Privileges Required
Low8 (17.0%)
High9 (19.1%)
None28 (59.6%)
Unknown2 (4.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Busybox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Busybox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Busybox's Products

View all 4 CNAs →

Top CWEs