CVE-2026-62947
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
वीकनेस
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
प्रभावित प्रोडक्ट
- openwrt openwrt
संदर्भ
- https://github.com/openwrt/cgi-io/commit/72990b7489872112df31c94032637c907760bae4
- https://github.com/openwrt/cgi-io/pull/4
- https://github.com/openwrt/openwrt/releases/tag/v25.12.5
- https://github.com/openwrt/openwrt/security/advisories/GHSA-jw5r-xhf5-2xcq
- https://github.com/openwrt/openwrt/security/advisories/GHSA-jw5r-xhf5-2xcq
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।