Critical severity9.8NVD Advisory· Published Aug 5, 2022· Updated Jun 17, 2026
CVE-2022-26376
CVE-2022-26376
Description
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- cpe:2.3:o:asus:gt-ax11000_pro_firmware:*:*:*:*:*:*:*:*Range: <3.0.0.4.386_48996
- cpe:2.3:o:asus:gt-axe16000_firmware:*:*:*:*:*:*:*:*Range: <3.0.0.4.386_48786
- cpe:2.3:o:asus:tuf-ax3000_v2_firmware:*:*:*:*:*:*:*:*Range: <3.0.0.4.386_48750
- Range: <386.7
- Range: prior to 386.7
Patches
Vulnerability mechanics
References
1- talosintelligence.com/vulnerability_reports/TALOS-2022-1511nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.