VYPR
High severity8.1NVD Advisory· Published Mar 16, 2020· Updated Jun 17, 2026

CVE-2020-7982

CVE-2020-7982

Description

An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Openwrt/opkgllm-create
    Range: <2020-01-25
  • Openwrt/Openwrtllm-fuzzy3 versions
    18.06.0 to 18.06.6, 19.07.0, 17.01.0 to 17.01.7+ 2 more
    • (no CPE)range: 18.06.0 to 18.06.6, 19.07.0, 17.01.0 to 17.01.7
    • cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*range: >=18.06.0,<18.06.7
    • cpe:2.3:o:openwrt:openwrt:19.07.0:-:*:*:*:*:*:*
  • LEDE/LEDEllm-create
    Range: 17.01.0 to 17.01.7
  • OpenWrt/OpenWrtdescription
  • cpe:2.3:a:openwrt:lede:*:*:*:*:*:*:*:*
    Range: >=17.01.0,<=17.01.7

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.