Executive brief
BusyBox, a widely used suite of software tools for embedded systems, contains a vulnerability in its 'wget' utility. An attacker can provide a specially crafted web address (URL) that tricks the tool into sending unauthorized commands or headers to a web server. This could allow an attacker to bypass security checks, poison web caches, or access restricted data.
Technical details
BusyBox wget through version 1.37.0 fails to sanitize raw CR (0x0D), LF (0x0A), and other C0 control bytes, as well as raw spaces (0x20), in the HTTP request-target (path/query). An attacker who can influence the URL passed to wget—either directly or via a redirect—can inject CRLF sequences to split the HTTP request line. This allows for the injection of arbitrary HTTP headers (such as Authorization or X-Forwarded-For), which can lead to cache poisoning, security policy bypasses, or credential exposure. The vulnerability is addressed by rejecting control characters and raw spaces in the request-target, requiring clients to use proper percent-encoding.
Affected products
- BusyBox BusyBox up to and including 1.37.0
Timeline
- 2025-08-23: disclosed: Initial report to BusyBox mailing list
- 2025-11-10: advisory: CVE published
References
- https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092
- https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm
- https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html