Deciso OPNsense是荷兰Deciso公司的一个防火墙与路由器操作系统。 Deciso OPNsense 26.1.7之前版本存在参数注入漏洞,该漏洞源于XMLRPC方法opnsense.restore_config_section未能清理用户提供的输入,导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45158 | 9.1 CRITICAL | OPNsense: Command Injection via Attacker-Controlled DHCP Config |
| CVE-2026-44194 | 9.1 CRITICAL | OPNsense: RCE on user managment |
| CVE-2026-44195 | 5.3 MEDIUM | OPNsense: Authentication lockout bypass |
No comments yet