CVE-2025-60876: n/a
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
AI Analysis
Technical Summary
BusyBox wget versions up to 1.3.7 improperly handle raw CR (0x0D), LF (0x0A), and other C0 control characters in the HTTP request-target (path/query). This flaw allows an attacker to split the HTTP request line and inject arbitrary headers by exploiting the acceptance of these control bytes. The vulnerability arises because wget does not reject raw spaces (0x20) in the request-target, which should be encoded as %20 to maintain the HTTP/1.1 request-line format 'METHOD SP request-target SP HTTP/1.1'. This can lead to header injection attacks. The CVSS 3.1 base score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, no privileges or user interaction required, and impacts confidentiality and integrity. No patch or vendor advisory is currently available.
Potential Impact
An attacker can exploit this vulnerability to inject arbitrary HTTP headers by splitting the HTTP request line, potentially leading to information disclosure or manipulation of HTTP requests made by BusyBox wget. The impact affects confidentiality and integrity but does not affect availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using vulnerable versions of BusyBox wget or implement network-level controls to detect and block malicious HTTP request patterns that include raw CR/LF characters in request-targets. Encoding spaces as %20 in URLs is recommended to avoid triggering the vulnerability.
CVE-2025-60876: n/a
Description
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
CVSS v3.1
Score 6.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
BusyBox wget versions up to 1.3.7 improperly handle raw CR (0x0D), LF (0x0A), and other C0 control characters in the HTTP request-target (path/query). This flaw allows an attacker to split the HTTP request line and inject arbitrary headers by exploiting the acceptance of these control bytes. The vulnerability arises because wget does not reject raw spaces (0x20) in the request-target, which should be encoded as %20 to maintain the HTTP/1.1 request-line format 'METHOD SP request-target SP HTTP/1.1'. This can lead to header injection attacks. The CVSS 3.1 base score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, no privileges or user interaction required, and impacts confidentiality and integrity. No patch or vendor advisory is currently available.
Potential Impact
An attacker can exploit this vulnerability to inject arbitrary HTTP headers by splitting the HTTP request line, potentially leading to information disclosure or manipulation of HTTP requests made by BusyBox wget. The impact affects confidentiality and integrity but does not affect availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid using vulnerable versions of BusyBox wget or implement network-level controls to detect and block malicious HTTP request patterns that include raw CR/LF characters in request-targets. Encoding spaces as %20 in URLs is recommended to avoid triggering the vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-09-26T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6912465f941466772c506b6f
Added to database: 11/10/2025, 20:09:03 UTC
Last enriched: 06/02/2026, 20:05:31 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 636
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.