CVE-2018-1000500: High severity busybox vulnerability
Published Jun 26, 2018
·Updated
Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".
Affected Software
2 affected components
Busybox Busybox<1.32.0
debian/busybox<=1:1.30.1-6, <=1:1.30.1-6+deb11u1, <=1:1.35.0-4, <=1:1.37.0-6
Remediation
Event History
Jun 26, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:45 PM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·12:52 PM
RemedyDescriptionSeverityAffected Software
Jun 17, 2025
Data Sourced
via Debian·03:44 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-1000500.
2
What is the severity of CVE-2018-1000500?
The severity of CVE-2018-1000500 is high with a severity value of 8.1.
3
What is the affected software for CVE-2018-1000500?
The affected software for CVE-2018-1000500 is Busybox.
4
How can CVE-2018-1000500 be exploited?
CVE-2018-1000500 can be exploited by simply downloading any file over HTTPS using "busybox wget" command.
5
Are there any remedies available for CVE-2018-1000500?
No specific remedies are mentioned for CVE-2018-1000500 in the provided information.