Path Traversal Vulnerability in OpenWrt's luci-app-bmx7
CVE-2026-69095

8.7HIGH

Key Information:

Vendor

Openwrt

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-69095?

The luci-app-bmx7 version prior to commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability within the bmx7-info CGI script. This security flaw enables unauthenticated attackers to exploit directory traversal sequences within the query string, permitting them to access files located outside of the designated runtime directory. Consequently, sensitive files that the CGI process can reach become exposed, posing significant risks to the integrity and confidentiality of the system.

Affected Version(s)

luci 0 < 5890760a454dad2cb00389dba2cdc5e779e0ffdd

luci 5890760a454dad2cb00389dba2cdc5e779e0ffdd

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nebusecurity
.