CVE Tools

CVE-2026-62947

OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download

Published: Jul 15, 2026Updated: Jul 21, 2026 Sources: CVE List NVDCWE-22

Description

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.

In plain language

AI Act now

CVE-2026-62947 is an OpenWrt bug that can let an attacker bypass access rules in the cgi-io download feature and read sensitive system files like /etc/shadow; small businesses running vulnerable OpenWrt versions should act now because it’s been tied to Lazarus-related targeting and fixed in OpenWrt 25.12.5.

Executive summary

In OpenWrt’s cgi-io cgi-download handler, a logic flaw allows an ACL bypass and then arbitrary root file read by authorizing the requested path before path canonicalization and using fnmatch() in rpcd session.c in a way that enables traversal through allowed wildcard patterns; fixed in OpenWrt 25.12.5.

If affected, business impact
Password/hash theftFull device compromise riskUnauthorized access to servicesIncident response and downtime

What to do now

  1. Check your OpenWrt version and confirm whether it is earlier than 25.12.5.
  2. If you are below 25.12.5, plan an upgrade to OpenWrt 25.12.5 (this is the fixed version).
  3. After upgrading, verify that the system is running on 25.12.5 and that the cgi-io component is updated as part of the firmware update.
  4. If you cannot upgrade immediately, restrict access to the affected HTTP CGI functionality from the internet (only allow trusted networks) and monitor for suspicious cgi-download requests and unusual file reads.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:HUI:NS:UC:HI:NA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

openwrt
oss-project·DEaka lede

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Collection
Discovery
View detailed technique mapping

References

and 1 more references View all →
3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-62947 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store