Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wget | Aug 8, 2025 | Nov 19, 2024 |
| Debian | — | Upgrade wgetNo solution exists | May 15, 2025 | Nov 19, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade wget | May 13, 2025 | Nov 19, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade wget | Apr 11, 2025 | Nov 19, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade wget | Mar 19, 2025 | Nov 19, 2024 |
| Huawei Euleros 2_0_sp13 | — | Upgrade wget | Apr 1, 2025 | Nov 19, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade wget | Mar 18, 2025 | Nov 19, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 19, 2024 |
| Suse | — | Upgrade wget-langUpgrade wget | Dec 31, 2024 | Nov 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub