CVE-2022-48174: Busybox

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

Affected products

  • Busybox Busybox: up to and including 1.36.1
  • Debian Debian Linux: version 11.0 only

Published 2023-08-22. Last modified 2026-07-14.