Unknown · Luci-App-Bmx7 · CVE-2026-69095
**Name of the Vulnerable Software and Affected Versions**
luci-app-bmx7 versions prior to commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd
**Description**
A path traversal issue exists in the `bmx7-info` CGI script. This allows unauthenticated attackers to read files outside the configured `runtimeDir` by supplying directory traversal sequences in the query string, enabling access to sensitive files accessible to the CGI process.
**Recommendations**
Update to the version containing commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd.