Vulnerability Intelligence Report
CVE-2017-16544
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:6.24%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94 Improper Control of Generation of Code ('Code Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| busybox | busybox | all |
| debian | debian_linux | 8.0, 9.0 |
| vmware | esxi | 6.0, 6.5, 6.7 |
| redlion | n-tron_702-w_firmware | all |
| redlion | n-tron_702-w | all |
| redlion | n-tron_702m12-w_firmware | all |
| redlion | n-tron_702m12-w | all |
| canonical | ubuntu_linux | 14.04, 16.04 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
6.240%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2017-11-05T00:00:00 |
| Published | 2017-11-20T15:00:00 |
| Patch Date | 2017-11-20 |
| Last Updated | 2025-06-09T15:35:03 |
Community Chatter & Buzz