VYPR
High severity7.5NVD Advisory· Published Sep 19, 2022· Updated Jun 17, 2026

CVE-2022-38333

CVE-2022-38333

Description

Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.

Affected products

3
  • Openwrt/Openwrtllm-fuzzy3 versions
    <v21.02.3, v22.03.0-rc6+ 2 more
    • (no CPE)range: <v21.02.3, v22.03.0-rc6
    • cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*range: <21.02.3
    • cpe:2.3:o:openwrt:openwrt:22.03.0:rc6:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.