PT-2023-14603 · Refirm+2 · Binwalk+2

·

CVE-2022-4510

·

Published

2023-01-25

·

Updated

2026-07-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions binwalk versions 2.1.2b through 2.3.3
Description binwalk is susceptible to a path traversal vulnerability. An attacker can exploit this by crafting a malicious PFS filesystem file, which allows them to extract files to arbitrary locations when binwalk is run in extraction mode (using the -e option). This can lead to remote code execution by extracting a malicious binwalk module into the .config/binwalk/plugins folder. The vulnerability is associated with the src/binwalk/plugins/unpfs.py file.
Recommendations Upgrade to a version of binwalk newer than 2.3.3.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-4837
ALT-PU-2024-8902
ALT-PU-2025-1936
CVE-2022-4510
DLA-3339-1
DLA-4410-1
GHSA-3CM8-V4MC-GPPG
MGASA-2023-0074
OPENSUSE-SU-2024:12649-1
PYSEC-2026-787

Affected Products

Alt Linux
Debian
Binwalk