CVE-2026-76014: BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference

Published Aug 19, 2026
·
Updated

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATUREWGETTIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff. A patch should be applied to remediate this issue.

Affected Software

1 affected component
Busybox Busybox<=1.30.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade BusyBox to a version that resolves this vulnerability.

    Patch 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff

Event History

Aug 19, 2026
CVE Published
via MITRE·02:45 AM
Data Sourced
via MITRE·02:45 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems running BusyBox versions up to 1.30.1 are affected where the wget FEATURE_WGET_TIMEOUT handler is present. Exploitation requires local access and low privileges.

2

What does an attacker need to do to trigger the flaw?

The attacker needs to invoke wget with a manipulated -T argument. Successful triggering causes a null pointer dereference and can affect availability.

3

Is public exploit information available?

Yes. The exploit has been publicly disclosed and may be used.

4

What should be done if the affected version is in use?

Apply patch 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff to remediate the issue. Until patching is possible, restrict local low-privileged access to systems that expose the affected BusyBox wget functionality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203