An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-03-16 22:15
Updated : 2021-07-21 11:39
NVD link : CVE-2020-7982
Mitre link : CVE-2020-7982
JSON object : View
Products Affected
openwrt
- openwrt
- lede
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
