<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OPNsense (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/opnsense.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/opnsense-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OPNsense (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:47 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45158 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45158</guid>
    <pubDate>Wed, 13 May 2026 22:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45158</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44194 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44194</guid>
    <pubDate>Wed, 13 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44194</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formatting their malicious payload as a compliant email address, allowing shell commands to reach the underl…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44193 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44193</guid>
    <pubDate>Wed, 13 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44193</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34578 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34578</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34578</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_escape(). An unauthenticated attacker can inject LDAP filter metacharacters into the username field of the WebGUI login page to enumerate valid LDAP usernames in the configured directory. When the LD…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-50989 – OPNsense before 25.1.8 contains an authenticated command injection vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50989</guid>
    <pubDate>Wed, 27 Aug 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-50989</strong></p>
  <p>OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowing an administrator to inject arbitrary shell operators and payloads. Successful exploitation results in remote code execution with the…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-27152 – DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27152</guid>
    <pubDate>Mon, 23 Oct 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-27152</strong></p>
  <p>DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39008 – A command injection vulnerability in the component /api/cron/settings/setJob/ of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39008</guid>
    <pubDate>Wed, 09 Aug 2023 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39008</strong></p>
  <p>A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39007 – /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39007</guid>
    <pubDate>Wed, 09 Aug 2023 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39007</strong></p>
  <p>/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39005 – Insecure permissions exist for configd.socket in OPNsense Community Edition befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39005</guid>
    <pubDate>Wed, 09 Aug 2023 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39005</strong></p>
  <p>Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39004 – Insecure permissions in the configuration directory (/conf/) of OPNsense Communi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39004</guid>
    <pubDate>Wed, 09 Aug 2023 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39004</strong></p>
  <p>Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39003 – OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39003</guid>
    <pubDate>Wed, 09 Aug 2023 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39003</strong></p>
  <p>OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39001 – A command injection vulnerability in the component diag_backup.php of OPNsense C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39001</guid>
    <pubDate>Wed, 09 Aug 2023 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39001</strong></p>
  <p>A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38997 – A directory traversal vulnerability in the Captive Portal templates of OPNsense ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38997</guid>
    <pubDate>Wed, 09 Aug 2023 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38997</strong></p>
  <p>A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11816 – Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11816</guid>
    <pubDate>Mon, 20 May 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11816</strong></p>
  <p>Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000479 – pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000479</guid>
    <pubDate>Wed, 03 Jan 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000479</strong></p>
  <p>pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000479">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
