---
id: CVE-2026-69095
title: >-
  OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd
  contains a path traversal vulnerability in the bmx7-info CGI script that
  allows unauthenticated attackers to read files outside the configured
  runtimeDir
summary: >-
  OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd
  contains a path traversal vulnerability in the bmx7-info CGI script that
  allows unauthenticated attackers to read files outside the configured
  runtimeDir. Attac…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-08-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:35:08.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-69095'
references:
  - url: 'https://github.com/openwrt/luci/security/advisories/GHSA-8qcq-jgrj-gvmj'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openwrt-luci-app-bmx7-path-traversal-via-bmx7-info
    label: disclosure@vulncheck.com
  - url: 'https://github.com/openwrt/luci/security/advisories/GHSA-8qcq-jgrj-gvmj'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00757
epssPercentile: 0.53738
ingestedAt: '2026-09-09T21:22:45.521Z'
---

## Overview

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
