CVE-2026-62947
OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
No known exploitation. EPSS puts it in the 42nd percentile. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check your OpenWrt version and confirm whether it is earlier than 25.12.5.
- If you are below 25.12.5, plan an upgrade to OpenWrt 25.12.5 (this is the fixed version).
- After upgrading, verify that the system is running on 25.12.5 and that the cgi-io component is updated as part of the firmware update.
- If you cannot upgrade immediately, restrict access to the affected HTTP CGI functionality from the internet (only allow trusted networks) and monitor for suspicious cgi-download requests and unusual file reads.
What it is
From the CVE record
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
In plain language
Written by AI from the recordCVE-2026-62947 is an OpenWrt bug that can let an attacker bypass access rules in the cgi-io download feature and read sensitive system files like /etc/shadow; small businesses running vulnerable OpenWrt versions should act now because it’s been tied to Lazarus-related targeting and fixed in OpenWrt 25.12.5.
In OpenWrt’s cgi-io cgi-download handler, a logic flaw allows an ACL bypass and then arbitrary root file read by authorizing the requested path before path canonicalization and using fnmatch() in rpcd session.c in a way that enables traversal through allowed wildcard patterns; fixed in OpenWrt 25.12.5.
If you're affected
- Password/hash theft
- Full device compromise risk
- Unauthorized access to services
- Incident response and downtime
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
0.5% chance of exploitation activity in the next 30 days, which ranks it in the 42nd percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
7 events over 6 days, from the signal feeds we watch.
- Patch availablerecord updated
- Publishedweakness classified, att&ck mapped, record updated, record updated
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Scored 4.9 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required HighRequires admin or elevated privileges
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity NoneNo integrity impact
- Availability NoneNo availability impact
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
- github.com/openwrt/cgi-io/commit/72990b7489872112df31c94032637c907760bae4
- github.com/openwrt/cgi-io/pull/4
- github.com/openwrt/openwrt/releases/tag/v25.12.5
And 1 more reference. See all after sign-in
In the news
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Openwrt, not every advisory.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI