Improper Neutralization of Special Elements in Output Used by a Downstream Component in OpenWrt and LEDE - CVE-2020-7982

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in OpenWrt and LEDE - CVE-2020-7982

Published: March 25, 2020


Vulnerability identifier: #VU26370
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2020-7982
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: openwrt.org
Affected software:
OpenWrt
LEDE

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in the OPKG package manager due to the way it performs integrity checking of downloaded packages using the SHA-256 checksums embedded in the signed repository index. A remote attacker can perform a man-in-the-middle attack, inject arbitrary package payloads and execute arbitrary code on the target system.


How to mitigate CVE-2020-7982

Install updates from vendor's website.

Sources