// 2 CRITICAL · 4 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
Trend Micro's Zero Day Initiative published advisory ZDI-26-705 on September 17, 2026, detailing a zero-day vulnerability in the BusyBox utility suite. The flaw, residing in the integrated libarchive component, allows remote attackers to create arbitrary files on vulnerable systems via a symlink-based directory traversal. The vendor did not confirm receipt of the initial report sent on October 3, 2025, nor a follow-up request on October 10, 2025.

Trend Micro published advisory ZDI-26-705 on September 17, 2026, covering a zero-day vulnerability in the BusyBox utility suite. The defect, originally reported on October 3, 2025, allows a remote attacker to create arbitrary files on vulnerable installations by exploiting a directory traversal via symlink in the libarchive component. The vendor had not confirmed receipt of the report as of the October 10, 2025 follow-up.

Key Takeaways
  • Advisory ZDI-26-705 addresses a zero-day vulnerability in BusyBox enabling arbitrary file creation
  • The attack mechanism exploits a symlink-based directory traversal in the libarchive component
  • Initial report sent to vendor on October 3, 2025; ZDI requested receipt confirmation on October 10, 2025 with no documented response
  • The brief contains no details on CVSS score, CVE identifier, or available patch

BusyBox integrates a version of libarchive for handling compressed archives. The vulnerability identified by ZDI resides in this specific component. The flaw allows an attacker to manipulate symbolic links within an archive to force the writing of files to arbitrary paths on the target filesystem. This mechanism, known as symlink directory traversal, bypasses path normalization checks that should confine extraction operations to the destination directory.

The ability to create arbitrary files represents a fundamental vector: from overwriting system files to potentially planting malicious components in executable paths. The remote nature of the attack condition expands the exposed surface, particularly in scenarios where BusyBox processes archives from untrusted sources.

BusyBox: A Ubiquitous Target in Embedded Infrastructure

BusyBox is a standard suite of utilities for Linux embedded systems, lightweight containers, and IoT devices. Its prevalence in routers, NAS devices, build systems, and containerized environments makes it a critical component in the open-source ecosystem. The inclusion of libarchive within the suite extends the attack surface to any workflow involving automated archive extraction.

The absence of details on specific affected versions in the brief prevents narrowing the impact to a subset of the installed base. ZDI classifies the condition as a zero-day, indicating that no official vendor-coordinated fix was available at the time of the advisory's publication.

The Disclosure Timeline: Vendor Silence

The documented chronology shows a disclosure process that dragged on without maintainer confirmation. ZDI transmitted the report on October 3, 2025, and pressed the vendor to confirm receipt on October 10, 2025. The brief records no subsequent responses or negotiations in the vulnerability's handling.

This timeline is significant: the interval between report and publication exceeds ten months, a span that in coordinated disclosure contexts raises questions about the project's capacity to absorb structured security reports. The vendor silence, documented at the follow-up point, stands as an objective datum in the ZDI timeline.

Why It Matters

The dossier does not specify the nature of exposed data nor the risk profile for specific user categories. The brief documents no specific remediation measures, workarounds, or verifiable indicators of compromise. No information on in-the-wild exploits or active attack campaigns leveraging this flaw appears in the available material.

The absence of a CVE identifier in the advisory's structured field, combined with the lack of a CVSS score, limits immediate readability of severity under standard frameworks. The brief does not clarify whether this absence reflects a ZDI choice or a processing state at MITRE.

What the document confirms is the presence of a zero-day defect in a widely distributed component, with a reproducible attack mechanism and documented impact on filesystem integrity. The advisory's publication without a coordinated patch exposes the installed base to a risk window not quantifiable in standard vulnerability management terms.

On October 10, 2025, ZDI pressed the vendor to confirm receipt of the report; the brief documents no response.

The Management Horizon: What the Dossier Does Not Clarify

The source does not specify whether the BusyBox maintainer subsequently responded to the follow-up or if private vulnerability handling is underway. The brief reveals no infrastructure overlaps with other known or publicly cataloged libarchive vulnerabilities. The credit field in the ZDI data structure is empty, preventing attribution of the research to a specific researcher or group.

The open-source nature of the project also raises the question of remediation responsibility: BusyBox is maintained by a small team relative to its massive industrial adoption, a recurring pattern in embedded software that makes response times to security reports variable and often unpredictable.

For security operators, the primary limitation lies in the lack of elements for prioritization: without CVSS, without CVE, and without confirmation of affected versions, risk assessment remains qualitative and tied to the specific exposure context of each environment.

Information is based on the cited advisory and current as of publication.

Sources

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. zerodayinitiative.com