An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag:
List of frequently cited URLs
User | URL | Info Source | Date |
---|---|---|---|
threatintelctr | https://nvd.nist.gov/vuln/detail/CVE-2020-7982 | Source threatintelctr 1516079920283373574 | 2022/04/19 |
RemotelyAlerts | http://alerts.remotelyrmm.com/CVE-2020-7982 | Source RemotelyAlerts 1516093473111228417 | 2022/04/19 |
WolfgangSesin | http://www.sesin.at | Source WolfgangSesin 1516108116622188544 | 2022/04/19 |
WolfgangSesin | https://www.sesin.at/2022/04/18/cve-2020-7982-lede-openwrt | Source WolfgangSesin 1516108116622188544 | 2022/04/19 |
www_sesin_at | http://www.sesin.at | Source www_sesin_at 1516108176101359620 | 2022/04/19 |
www_sesin_at | https://www.sesin.at/2022/04/18/cve-2020-7982-lede-openwrt | Source www_sesin_at 1516108176101359620 | 2022/04/19 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
newsbythehour.org | 24 |
canyoupwn.me | 13 |
twitter.com | 5 |
blog.forallsecure.com | 4 |
www.reddit.com | 3 |
www.helpnetsecurity.com | 3 |
User | URL | Info Source |
---|---|---|
threatintelctr | nvd.nist.gov | Show Tweet |
RemotelyAlerts | alerts.remotelyrmm.com | Show Tweet |
WolfgangSesin | sesin.at | Show Tweet |
WolfgangSesin | sesin.at | Show Tweet |
www_sesin_at | sesin.at | Show Tweet |
www_sesin_at | sesin.at | Show Tweet |
Name | URL |
---|---|
No Data |
Name | URL |
---|---|
No Data |