cbcvebase.
CVE-2022-26376
published 2022-08-05

CVE-2022-26376: A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

Affected

20 ranges
VendorProductVersion rangeFixed in
asusasuswrt< 3.0.0.4.386_487063.0.0.4.386_48706
asuset12_firmware< 3.0.0.4.386_488233.0.0.4.386_48823
asusgt-ax11000_firmware< 3.0.0.4.386_495593.0.0.4.386_49559
asusgt-ax11000_pro_firmware< 3.0.0.4.386_489963.0.0.4.386_48996
asusgt-ax6000_firmware< 3.0.0.4.386_488233.0.0.4.386_48823
asusgt-axe16000_firmware< 3.0.0.4.386_487863.0.0.4.386_48786
asusrt-ax55_firmware< 3.0.0.4.386_495593.0.0.4.386_49559
asusrt-ax56u_firmware< 3.0.0.4.386_495593.0.0.4.386_49559
asusrt-ax58u_firmware< 3.0.0.4.386_489083.0.0.4.386_48908
asusrt-ax68u_firmware< 3.0.0.4.386_494793.0.0.4.386_49479
asusrt-ax82u_firmware< 3.0.0.4.386_493803.0.0.4.386_49380
asusrt-ax86u_firmware< 3.0.0.4.386_494473.0.0.4.386_49447
asustuf-ax3000_v2_firmware< 3.0.0.4.386_487503.0.0.4.386_48750
asusxd4_firmware< 3.0.0.4.386_487903.0.0.4.386_48790
asusxd6_firmware< 3.0.0.4.386_493563.0.0.4.386_49356
asusxt12_firmware< 3.0.0.4.386_488233.0.0.4.386_48823
asusxt8_firmware< 3.0.0.4.386_487063.0.0.4.386_48706
asusxt9_firmware< 3.0.0.4.388_200273.0.0.4.388_20027
asuswrt-merlinasuswrt-merlin_new_gen
asuswrt-merlinnew_gen< 386.7386.7