top of page
perceptive_background_267k.jpg

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows una…

Published:

2 August 2026 at 22:00:00

Alert date:

3 August 2026 at 15:06:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Web Technologies

A path traversal vulnerability exists in OpenWrt's luci-app-bmx7 package prior to commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd. The flaw resides in the bmx7-info CGI script and allows unauthenticated attackers to read arbitrary files outside the configured runtimeDir. Exploitation is achieved by supplying directory traversal sequences in the HTTP query string, enabling escape from the intended directory boundary. Sensitive files accessible to the CGI process can be read without any authentication. The vulnerability affects OpenWrt routers and embedded devices running the affected luci-app-bmx7 package. A fix has been committed and is referenced by the specific commit hash. The issue is documented in a GitHub Security Advisory and a VulnCheck advisory. No active exploitation has been publicly confirmed at this time, but the unauthenticated nature of the attack raises the criticality level.

Technical details

Mitigation steps:

Affected products:

OpenWrt luci-app-bmx7

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page