PT-2026-67417 · Unknown · Luci-App-Bmx7

·

CVE-2026-69095

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions luci-app-bmx7 versions prior to commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd
Description A path traversal issue exists in the bmx7-info CGI script. This allows unauthenticated attackers to read files outside the configured runtimeDir by supplying directory traversal sequences in the query string, enabling access to sensitive files accessible to the CGI process.
Recommendations Update to the version containing commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69095

Affected Products

Luci-App-Bmx7