CVE-2026-22905

An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g., /js/../cgi-bin/post.cgi), gaining unauthorized access to protected CGI endpoints and configuration downloads.
Configurations

No configuration.

History

09 Feb 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 08:16

Updated : 2026-02-09 16:08


NVD link : CVE-2026-22905

Mitre link : CVE-2026-22905

CVE.ORG link : CVE-2026-22905


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')