Our takeCERT-Bund flags multiple flaws in BusyBox that let a remote attacker cause DoS or tamper with files. Update to a fixed version if you ship embedded BusyBox in your devices or containers.Cyber Resilience desk
Sources (17)
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
What this means for you — Security leader:Inventory embedded devices, appliances, and container images that ship BusyBox; apply vendor firmware or base-image updates that include the fixed builds. Prioritize internet-exposed and OT/edge systems where anonymous remote DoS or file manipulation is in scope.
What this means for you — Lean IT orgs:Check firmware updates for routers, NAS, and similar appliances you manage—many embed BusyBox. If you only use hosted cloud services with no on-prem appliances, you can ignore this.
What this means for you — MSP:Scan client estates for BusyBox in appliance firmware and container base images; schedule vendor firmware and image refreshes, starting with internet-facing and shared-edge gear.
What this means for you — Researcher:Pull WID-SEC-2025-0879 for the affected BusyBox versions and CVE list; issues cover remote anonymous DoS and file manipulation worth tracking in embedded and container supply chains.