Developer Tools & Libraries

Remote Code Execution

Path Traversal in Binwalk WinCE Extraction Leading to Arbitrary File Write and Code Execution

This vulnerability allows an attacker to craft a malicious firmware image that writes files outside the intended extraction directory when processed by a vulnerable Binwalk installation.

5.3
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS101
PUBLISHED
2026-05-27
CVE IDs
CVE-2026-7179
VENDORS
OSPG / ReFirmLabs
PUBLIC EXPLOIT
None indexed
CWE
CWE-22
PRODUCT
Binwalk
CVSS VECTOR
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Binwalk version 2.4.3 and prior versions contain a path traversal vulnerability in the WinCE ROM extraction functionality. The vulnerable code reads file names directly from a WinCE ROM image and uses them while creating extracted output files without proper path sanitization or boundary validation.

An attacker can craft a malicious firmware image containing file entries with directory traversal sequences such as ../. When a user extracts the firmware using Binwalk, the vulnerable extraction logic writes files outside the intended extraction directory. This results in arbitrary file write on the victim's system.

The issue occurs because file names parsed from the firmware are trusted and passed directly into file-writing operations without using safe path checks such as basename validation, canonical path comparison, or extraction-directory enforcement. This can further lead to code execution if the attacker writes a malicious Python file into a location automatically loaded by Binwalk during a later execution.

Vulnerability details

Vulnerability details

CVE-2026-7179
CWE-22
Medium | 5.3

Binwalk version 2.4.3 and prior versions contain a path traversal vulnerability in the WinCE ROM extraction functionality.

Auth:
Any authenticated user (local access)
Impact:
Limited data disclosure, limited data tampering, partial service degradation
Impact

What an attacker can do

This vulnerability allows an attacker to craft a malicious firmware image that writes files outside the intended extraction directory when processed by a vulnerable Binwalk installation. As a result: · Arbitrary File Write: An attacker can place attacker-controlled files in unintended locations on the victim's system. · Code Execution: By writing a malicious Python file into Binwalk's user plugin directory, the attacker can achieve code execution when Binwalk is executed again. · Security Researcher Compromise: Firmware analysts, CTF players, malware analysts, and security researchers may be compromised simply by extracting a malicious firmware image. · Integrity Impact: The attacker can overwrite or create files that alter tool behavior, user environment configuration, or analysis results. · Supply Chain and Analysis Pipeline Risk: Automated firmware analysis pipelines using vulnerable Binwalk versions may process malicious samples and become compromised.

DISCLOSURE

Disclosure timeline

2026-04-09 Vulnerability discovered

2026-04-10 Reported to maintainers

2026-04-27 CVE ID assigned

Credits

Dhabaleshwar Das – Payatu Security Consulting Pvt. Ltd.