CVE-2026-69095: OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attacke
OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69095
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69095 | coverage & exploitation status | NVD · CVE.org |
More from NVD Recent CVEs
- unknownCVE-2026-9487: XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_x…2026-08-03
- unknownCVE-2026-9390: XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_si…2026-08-03
- highCVE-2026-69097: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing a…2026-08-03
- highCVE-2026-69096: OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docke…2026-08-03
- mediumCVE-2026-69094: Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_t…2026-08-03