CVE detail
CVE-2026-62947
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 4
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
4 source links · newest first
No excerpt available.
Exploitgithub.comJul 15, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJul 15, 2026, 7:18 PM- https://github.com/openwrt/cgi-io/pull/4github.com
No excerpt available.
Exploitgithub.comJul 15, 2026, 7:18 PM No excerpt available.
Exploitgithub.comJul 15, 2026, 7:18 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-65754CVSS N/A · Unrated
ReReplacer XML include paths could read files outside the site directory.
- CVE-2026-65713CVSS N/A · Unrated
Modals gallery paths could enumerate unintended directories.
- CVE-2026-65712CVSS N/A · Unrated
CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.
- CVE-2026-65431CVSS N/A · Unrated
Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
- CVE-2026-64872CVSS N/A · Unrated
Custom purge and log paths could escape the site webroot directory.
- CVE-2026-16078CVSS 6.5 · Medium
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' paramet…