CVE-2026-62947
OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
Description
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
In plain language
AI Act nowCVE-2026-62947 is an OpenWrt bug that can let an attacker bypass access rules in the cgi-io download feature and read sensitive system files like /etc/shadow; small businesses running vulnerable OpenWrt versions should act now because it’s been tied to Lazarus-related targeting and fixed in OpenWrt 25.12.5.
In OpenWrt’s cgi-io cgi-download handler, a logic flaw allows an ACL bypass and then arbitrary root file read by authorizing the requested path before path canonicalization and using fnmatch() in rpcd session.c in a way that enables traversal through allowed wildcard patterns; fixed in OpenWrt 25.12.5.
What to do now
- Check your OpenWrt version and confirm whether it is earlier than 25.12.5.
- If you are below 25.12.5, plan an upgrade to OpenWrt 25.12.5 (this is the fixed version).
- After upgrading, verify that the system is running on 25.12.5 and that the cgi-io component is updated as part of the firmware update.
- If you cannot upgrade immediately, restrict access to the affected HTTP CGI functionality from the internet (only allow trusted networks) and monitor for suspicious cgi-download requests and unusual file reads.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- MEGANews. Cамые важные события в мире инфосека за августru-ru·Хакер (xakep.ru)· Exploited Dahua Cameras Lazarus
- В OpenWrt исправили критическую уязвимость в DHCPv6-сервереru-ru·Хакер (xakep.ru)· Patch OpenWrt odhcpd ics-ot-iot
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Rooten·The Hacker News· Patch odhcpd rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62947 and every CVE in our database. Create a free account — no credit card required.
Create Free Account