PT-2026-67417 · Unknown · Luci-App-Bmx7
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
luci-app-bmx7 versions prior to commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd
Description
A path traversal issue exists in the
bmx7-info CGI script. This allows unauthenticated attackers to read files outside the configured runtimeDir by supplying directory traversal sequences in the query string, enabling access to sensitive files accessible to the CGI process.Recommendations
Update to the version containing commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Luci-App-Bmx7