VYPR
Medium severity4.9NVD Advisory· Published Jul 15, 2026· Updated Jul 21, 2026

CVE-2026-62947

CVE-2026-62947

Description

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.

Affected products

3
  • Openwrt/Openwrt2 versions
    cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*range: <25.12.5
    • (no CPE)range: <25.12.5
  • Openwrt/cgi-iollm-create
    Range: <25.12.5

Patches

Vulnerability mechanics

References

4

News mentions

1