CVE-2018-1000517

CRITICAL

BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This ...

Affects 3 products across 3 vendors.

BCS7.78
CVSS 3.19.8
EPSS32.9%
Percentile98th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-120: Buffer Copy without Checking Size (Classic Buffer Overflow)

Program copies data to a buffer without verifying the source data fits within the destination.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2018. A critical vulnerability affects Busybox systems (CVE-2018-1000517). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2018-GLOBAL-123125-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2018-1000517?
This vulnerability was disclosed in 2018. A critical vulnerability affects Busybox systems (CVE-2018-1000517). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2018-1000517?
CVE-2018-1000517 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 32.9%.
Is CVE-2018-1000517 actively exploited?
No confirmed active exploitation of CVE-2018-1000517 as of 2026-05-30.
How do I remediate CVE-2018-1000517?
Priority: MEDIUM. Advisory: https://git.busybox.net/busybox/commit/?id=8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e PSIRT: [email protected]
What systems are affected by CVE-2018-1000517?
CVE-2018-1000517 affects: Busybox, Canonical, Debian.
Vulnerability Details
CVE IDCVE-2018-1000517
BSIDBS-2018-GLOBAL-123125-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2018-06-26
Last Modified2025-06-09
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in after commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in after commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e. CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Busybox Busybox
Canonical Ubuntu Linux
Debian Debian Linux
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 2938 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash7bbbd4c4f1447227db4201e859088e7217e737de5b71129bf884e61bd00b4df3f4399b9d9ff2863d6437871a8f0ac668b41dac255088a42479cbf24b7cf02f87
Related CVEs affecting Busybox
CVE-2022-48174 9.8 There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35.... CVE-2021-42377 9.8 An attacker-controlled pointer free in Busybox's hush applet leads to denial ... CVE-2016-2148 9.8 Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25... CVE-2022-28391 8.8 BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if n... CVE-2017-16544 8.8 In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the ...
View all Busybox CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →