Command injection in FreeBSD - CVE-2026-45255
Published: May 21, 2026
FreeBSD
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to command injection in Wi-Fi network name handling in bsdinstall and bsdconfig when scanning for nearby Wi-Fi networks. A remote attacker can create an access point with a specially crafted network name to execute arbitrary code.
User interaction is required to initiate a Wi-Fi scan, but the malicious network does not need to be selected.