Junglewise Threat Intelligence

CVE-2026-62947: OpenWrt cgi-io path traversal in cgi-download and cgi-exec

CVE-2026-62947 · Severity: medium · CVSS 4.9 · Published 2026-07-15

Technologies: OpenWrt. Vendors: OpenWrt.

Executive brief

OpenWrt is an open-source operating system used for routers and embedded devices. A security flaw in its file download and execution handlers allows an authorized user with limited file access to bypass security restrictions and read any file on the system, including sensitive credentials like password hashes. This could allow a restricted administrator to gain full control over the device.

Technical details

A path traversal vulnerability exists in the cgi-download and cgi-exec handlers of the cgi-io component in OpenWrt. The root cause is that the application performs Access Control List (ACL) validation against the requested path before canonicalizing it. Because the underlying rpcd session manager uses fnmatch() without the FNM_PATHNAME flag, an attacker can use a wildcard prefix followed by traversal sequences (e.g., /allowed/path/*/../../etc/shadow) to satisfy the ACL check while accessing files outside the intended directory. Since cgi-io runs with root privileges, this allows an authenticated user with at least one wildcard file-read grant to read any file on the filesystem or execute arbitrary binaries. The issue is fixed in OpenWrt 25.12.5 by ensuring paths are canonicalized before ACL checks.

Affected products

  • OpenWrt OpenWrt < 25.12.5

Timeline

  • 2026-06-27: patched: Fixes merged into cgi-io master branch.
  • 2026-07-01: advisory: OpenWrt 25.12.5 release announcement.
  • 2026-07-15: disclosed: CVE-2026-62947 published.

References

Related threats