Improper Neutralization of Special Elements in Output Used by a Downstream Component in OpenWrt and LEDE - CVE-2020-7982
Published: March 25, 2020
OpenWrt
LEDE
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the OPKG package manager due to the way it performs integrity checking of downloaded packages using the SHA-256 checksums embedded in the signed repository index. A remote attacker can perform a man-in-the-middle attack, inject arbitrary package payloads and execute arbitrary code on the target system.