CVE-2026-62947: Openwrt
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
Affected products
- Openwrt Openwrt: before 25.12.5 (fixed in 25.12.5)
Published 2026-07-15. Last modified 2026-07-21.