Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-62947

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*
Версия до 25.12.5 (исключая)

EPSS

Процентиль: 33%
0.00401
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22

EPSS

Процентиль: 33%
0.00401
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22