CVE-2022-26376: Critical severity asuswrt-merlin vulnerability
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.38648706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26376?
CVE-2022-26376 is a memory corruption vulnerability in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.
How severe is CVE-2022-26376?
CVE-2022-26376 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2022-26376?
Asuswrt versions prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen versions prior to 386.7 are affected.
How does CVE-2022-26376 work?
A specially-crafted HTTP request can lead to memory corruption, allowing an attacker to send a network request to exploit the vulnerability.
Is my Asus Xt8 firmware vulnerable to CVE-2022-26376?
No, the Asus Xt8 firmware is not vulnerable to CVE-2022-26376.