← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-28391

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:3.50%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-88 ↗CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Affected Products & Versions

Vendor Product Affected Versions
busybox busybox all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.505%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2022-04-03T00:00:00
Published2022-04-03T20:20:12
Last Updated2025-06-09T15:33:29

LINK COPIED TO CLIPBOARD