CVE-2026-76014 | CVSS: 3.3 | 严重级别: LOW
A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff. A patch should be applied to remediate this issue.
参考链接:
• https://gist.github.com/wyxstarry/5c199ec824928c5ae5816aaecbc6df03
• https://github.com/mirror/busybox/commit/83a40bf7a93c8ac093d33ab452222dd5b9eb57f
• https://github.com/mirror/busybox/issues/124
📌 数据来源: NVD 官方
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。