Improper Neutralization of Special Elements in Output Used by a Downstream Component in LEDE and OpenWrt - CVE-2020-7982
Published: March 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the OPKG package manager due to the way it performs integrity checking of downloaded packages using the SHA-256 checksums embedded in the signed repository index. A remote attacker can perform a man-in-the-middle attack, inject arbitrary package payloads and execute arbitrary code on the target system.
Affected software
OpenWrt