Executive brief
A vulnerability in the Garmin EmpirBus Wireless Display Unit (WDU) allows an attacker to access sensitive files on the device. By uploading a specially crafted graphics package containing symbolic links, an attacker can trick the device's internal web server into revealing files it should not share. This could lead to the exposure of system information or configuration data from the marine display unit.
Technical details
The vulnerability is a symlink attack (CWE-59) within the locally served web interface of the Garmin EmpirBus WDU. When a user or attacker uploads a graphics package containing symbolic links, the web server follows these links without verifying if the targets reside within the intended directory. Because there are no mechanisms to restrict link targets to a specific area of the filesystem, an unauthenticated network attacker can retrieve arbitrary files from the device. The issue affects WDU v1 version 1.4.6 and WDU v2 version 5.0.0, and was addressed in WDU v2 firmware version 5.41.
Affected products
- Garmin EmpirBus Wireless Display Unit (WDU) v1 firmware 1.4.6
- Garmin EmpirBus Wireless Display Unit (WDU) v2 firmware 5.0.0
Timeline
- 2026-04-02: patched: Fixed in EmpirBus WDUv2 software version 5.41 (and later version 7.00)
- 2026-05-13: disclosed: Initial CVE publication
- 2026-06-02: advisory: NVD analysis and CPE mapping updated