Developer Tools & Libraries
Remote Code Execution
Path Traversal in Binwalk WinCE Extraction Leading to Arbitrary File Write and Code Execution
This vulnerability allows an attacker to craft a malicious firmware image that writes files outside the intended extraction directory when processed by a vulnerable Binwalk installation.
.png)
Overview
Binwalk version 2.4.3 and prior versions contain a path traversal vulnerability in the WinCE ROM extraction functionality. The vulnerable code reads file names directly from a WinCE ROM image and uses them while creating extracted output files without proper path sanitization or boundary validation.
An attacker can craft a malicious firmware image containing file entries with directory traversal sequences such as ../. When a user extracts the firmware using Binwalk, the vulnerable extraction logic writes files outside the intended extraction directory. This results in arbitrary file write on the victim's system.
The issue occurs because file names parsed from the firmware are trusted and passed directly into file-writing operations without using safe path checks such as basename validation, canonical path comparison, or extraction-directory enforcement. This can further lead to code execution if the attacker writes a malicious Python file into a location automatically loaded by Binwalk during a later execution.
Vulnerability details
Binwalk version 2.4.3 and prior versions contain a path traversal vulnerability in the WinCE ROM extraction functionality.
What an attacker can do
This vulnerability allows an attacker to craft a malicious firmware image that writes files outside the intended extraction directory when processed by a vulnerable Binwalk installation. As a result: · Arbitrary File Write: An attacker can place attacker-controlled files in unintended locations on the victim's system. · Code Execution: By writing a malicious Python file into Binwalk's user plugin directory, the attacker can achieve code execution when Binwalk is executed again. · Security Researcher Compromise: Firmware analysts, CTF players, malware analysts, and security researchers may be compromised simply by extracting a malicious firmware image. · Integrity Impact: The attacker can overwrite or create files that alter tool behavior, user environment configuration, or analysis results. · Supply Chain and Analysis Pipeline Risk: Automated firmware analysis pipelines using vulnerable Binwalk versions may process malicious samples and become compromised.
Disclosure timeline
2026-04-09 Vulnerability discovered
2026-04-10 Reported to maintainers
2026-04-27 CVE ID assigned
References
Credits
Dhabaleshwar Das – Payatu Security Consulting Pvt. Ltd.
















