PT-2026-78263 · Busybox · Busybox

·

CVE-2026-76014

·

Published

2026-08-19

·

Updated

2026-08-25

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions BusyBox versions prior to 1.30.1
Description A null pointer dereference occurs in the FEATURE WGET TIMEOUT handler within the networking/wget.c file. This issue is triggered by the manipulation of the -T argument and requires local access to be exploited.
Recommendations Apply patch 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff to versions prior to 1.30.1.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76014
ECHO-1FCB-1955-3C69

Affected Products

Busybox