Vulnerabilities > Busybox > Busybox > 1.19.3

DATE CVE VULNERABILITY TITLE RISK
2012-07-03 CVE-2011-2716 Improper Input Validation vulnerability in multiple products
The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.
high complexity
t-mobile busybox CWE-20
6.8