漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
Vulnerability Description
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard prefix followed by ../ to read root-readable files including /etc/shadow. This vulnerability is fixed in 25.12.5.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
OpenWrt 路径遍历漏洞
Vulnerability Description
OpenWrt是OpenWRT社区开源的一套针对嵌入式设备的Linux操作系统。 OpenWrt 25.12.5之前版本存在路径遍历漏洞,该漏洞源于cgi-download处理器在规范化前未对请求路径进行适当授权,以及rpcd session.c使用fnmatch()时未使用FNM_PATHNAME参数,允许通过通配符前缀加../的方式进行路径遍历,导致可读取包括/etc/shadow在内的root可读文件。
CVSS Information
N/A
Vulnerability Type
N/A