Deciso OPNsense是荷兰Deciso公司的一套基于FreeBSD的开源防火墙和路由软件。 Deciso OPNsense 26.1.7之前版本存在安全漏洞,该漏洞源于lockout_handler中的逻辑缺陷,允许未经身份验证的攻击者通过插入包含成功关键字的用户名,持续重置其IP地址的身份验证失败计数器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45158 | 9.1 CRITICAL | OPNsense: Command Injection via Attacker-Controlled DHCP Config |
| CVE-2026-44193 | 9.1 CRITICAL | OPNsense: RCE via XMLRPC endpoint using `opnsense.restore_config_section` method |
| CVE-2026-44194 | 9.1 CRITICAL | OPNsense: RCE on user managment |
No comments yet