CVE-2026-62947 is a path traversal vulnerability in OpenWrt's cgi-io component that can expose arbitrary root-readable files. It requires an authenticated session with the cgi-io download permission and an applicable wildcard file-read grant. Fixed in OpenWrt 24.10.8 and 25.12.5.