ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability
Published Sep 16, 2026
·Updated
This vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-92205.
Affected Software
1 affected component
Busybox Busybox
Event History
Sep 16, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Can an attacker trigger this without involving a user?
The available information states that user interaction is required. The target must visit a malicious page or open a malicious file for exploitation to occur.