Vulnerability in OpenWrt Leads to Information Disclosure Risk
CVE-2022-38333

7.5HIGH

Key Information:

Vendor

Openwrt

Status
Vendor
CVE Published:
19 September 2022

What is CVE-2022-38333?

The vulnerability affects OpenWrt versions prior to v21.02.3 and v22.03.0-rc6 due to the presence of two skip loops in the header_value() function. Exploiting this flaw enables an attacker to craft specific HTTP requests that can expose sensitive information, leading to potential unauthorized access to critical data.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-38333 : Vulnerability in OpenWrt Leads to Information Disclosure Risk