Improper Neutralization of Argument Delimiters in a Command in OPNsense - CVE-2026-45158
Published: May 12, 2026
OPNsense
Deciso
Description
The vulnerability allows a remote user to execute arbitrary code as root.
The vulnerability exists due to improper neutralization of argument delimiters in the DHCP configuration handling in src/etc/inc/interfaces.inc when processing attacker-controlled DHCP hostname values through the web interface. A remote user can supply a crafted hostname value to execute arbitrary code as root.
Exploitation requires page-interfaces privileges and is triggered when changes are applied or when the interface later issues a DHCP request.