CVE-2022-48174
Critical · CVSS 9.8BusyBox — Stack overflow out-of-bounds write (CWE-787) leading to arbitrary code execution in ash shell
- CVSS
- 9.8
- nvd
- EPSS
- 2.98%
- 86th pct
- KEV
- No
- Class
- oss containerizable
- CWE-787
Description
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
Search profile — drives PoC discovery
Symbols ash.cash.c:6030busybox ashstack overflowash shellevalstringevalcommandevaltree
Keywords CVE-2022-48174BusyBox stack overflowbusybox ash shell exploitbusybox before 1.35 vulnerabilityash.c 6030 stack overflowbusybox IoV RCEbusybox arbitrary code executionbusybox PoC CVE-2022-48174
Versions: < 1.35.0
Ranked PoCs (4) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0ChrisAdkin8/Nomad-Job-Vulnerability-Tagging needs reviewtrickest
- ★ 0nqminds/SBOM-GAP needs reviewtrickest
- ★ 0nqminds/sbom-cli needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://bugs.busybox.net/show_bug.cgi?id=15216
- https://bugs.busybox.net/show_bug.cgi?id=15216
- https://lists.debian.org/debian-lts-announce/2025/01/msg00012.html
- https://security.netapp.com/advisory/ntap-20241129-0001/
- https://cert-portal.siemens.com/productcert/html/ssa-089022.html
- https://cert-portal.siemens.com/productcert/html/ssa-585531.html
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z