AI description
CVE-2026-45158 is a remote code execution vulnerability identified in OPNsense, a FreeBSD-based firewall and routing platform. This flaw stems from unsanitized user input being passed to the DHCP configuration of a configured interface. A shell script then processes this input, allowing for command injection. An authenticated attacker with high privileges can exploit this vulnerability by injecting shell commands through the DHCP input, leading to the execution of arbitrary code as root on the underlying operating system. The issue is classified under CWE-88 (Improper Neutralization of Argument Delimiters in a Command) and affects OPNsense versions prior to 26.1.8, where the vendor has addressed the vulnerability.
- Description
- OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- opnsense
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-88
- Hype score
- Not currently trending
CVE-2026-44194 & CVE-2026-45158: Two RCE vulnerabilities in OPNsense, 9.1 rating 🔥 Two vulnerabilities in OPNsense allows an authenticated attacker to execute arbitrary code as root on the firewall host via User management system (CVE-2026-44194) and DHCP Config https://t
@Netlas_io
15 May 2026
2555 Impressions
10 Retweets
34 Likes
11 Bookmarks
2 Replies
0 Quotes
OPNsenseに重大(Critical)な脆弱性2件。CVE-2026-44194はWebインターフェースのユーザ名にメールアドレスを指定した際のOSコマンドインジェクション。CVE-2026-45158はDHCP構成からのOSコマンドインジェクション。いずれも
@__kokumoto
14 May 2026
300 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Public PoC for OPNsense CVE-2026-44194 and CVE-2026-45158. Critical flaws allow root command execution via DHCP and User sync. Update to 26.1.8 now! #OPNsense #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #CVE #Firewall #OpenSource #RootExploit #PoC https://t.co/BfnGvOtwTS ht
@the_yellow_fall
14 May 2026
818 Impressions
5 Retweets
12 Likes
4 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A0EDE7AC-7C9D-4244-9120-DA3CDB7AAB2C",
"versionEndExcluding": "26.1.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]