OPNsense 是一个基于 FreeBSD 的防火墙与路由平台。在 opnsense/core 26.1.9 之前以及 BE/opnsense/core 26.4_20 之前,NTP 配置模块中存在一个路径遍历漏洞,允许攻击者以 root 用户身份覆盖系统中的任意文件。通过操纵 GPS 或 PPS 串口参数,拥有 NTP 配置访问权限的攻击者可以跳出预期目录,迫使系统将用户控制的数据写入文件系统中的任意文件。该问题已在 opnsense/core 26.1.9 和 BE/opnsense/core 26.4_20
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet