SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-69095

HIGH · CVSS 7.5 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The bmx7-info CGI script in OpenWrt luci-app-bmx7 prior to a specific commit is vulnerable to a path traversal attack, enabling unauthenticated attackers to read sensitive files outside the designated runtime directory. This vulnerability poses a significant risk as it allows access to potentially sensitive information on affected systems. Organizations using this version of OpenWrt should prioritize patching to mitigate the risk of unauthorized data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-69095
Severity
HIGH
CVSS
7.5
EPSS
0.62%

Original NVD Description

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.