VYPR

cgi-io

by Openwrt

CVEs (1)

  • CVE-2026-62947MedJul 15, 2026
    risk 0.00cvss 4.9epss 0.00

    OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing…