CVE-2017-16544

HIGH

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and r...

Affects 8 products across 5 vendors.

BCS7.03
CVSS 3.18.8
EPSS6.2%
Percentile93th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-94: Code Injection

Attacker injects arbitrary code that is executed by the application process.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2017. A high severity vulnerability affects Busybox systems (CVE-2017-16544). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2017-GLOBAL-117063-H • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2017-16544?
This vulnerability was disclosed in 2017. A high severity vulnerability affects Busybox systems (CVE-2017-16544). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2017-16544?
CVE-2017-16544 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 6.2%.
Is CVE-2017-16544 actively exploited?
No confirmed active exploitation of CVE-2017-16544 as of 2026-05-30.
How do I remediate CVE-2017-16544?
Priority: MEDIUM.
What systems are affected by CVE-2017-16544?
CVE-2017-16544 affects: Busybox, Canonical, Debian, Redlion, Redlion, Redlion, Redlion, Vmware.
Vulnerability Details
CVE IDCVE-2017-16544
BSIDBS-2017-GLOBAL-117063-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2017-11-20
Last Modified2026-05-13
ICS Relevance15%
Weakness (CWE)
Domains
CLOUD
SourceNVD
Official Description

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks. CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Busybox Busybox
Canonical Ubuntu Linux
Debian Debian Linux
Redlion N-Tron 702M12-W Firmware
Redlion N-Tron 702M12-W
Redlion N-Tron 702-W Firmware
Redlion N-Tron 702-W
Vmware Esxi
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3156 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash043b8d9ce2f65e3f5aa094125d85e53c92e6689621a75ae77a9b21615bdbfe3650c53c0380e294376e1fd50756f15385c6f7e73d8179b3d843620c71276f96bc
Related CVEs affecting Busybox
CVE-2021-42377 9.8 An attacker-controlled pointer free in Busybox's hush applet leads to denial ... CVE-2022-48174 9.8 There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35.... CVE-2016-2148 9.8 Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25... CVE-2018-1000517 9.8 BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e0... CVE-2022-28391 8.8 BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if n...
View all Busybox CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →