CVE-2025-27850: Garmin Empirbus Wireless Display Unit Firmware
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links when serving content. No mechanisms to restrict those link targets to a specific area of the filesystem is enabled. This allows an attacker to retrieve arbitrary files from the device.
Affected products
- Garmin Empirbus Wireless Display Unit Firmware: version 1.4.6 only; version 5.00 only
Published 2026-05-13. Last modified 2026-06-17.