Path traversal in OPNsense - #VU134540

 

Path traversal in OPNsense - #VU134540

Published: June 15, 2026


Vulnerability identifier: #VU134540
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Deciso
Affected software:
OPNsense

Detailed vulnerability description

The vulnerability allows a remote user to create or overwrite root-owned files outside the intended IPsec certificate directories.

The vulnerability exists due to path traversal in Trust certificate refid handling in IPsec file generation when processing attacker-controlled certificate references during IPsec reconfiguration. A remote user can supply a crafted refid value to create or overwrite root-owned files outside the intended IPsec certificate directories.

Exploitation requires access to Trust certificate management and IPsec configuration, and the created files retain fixed .key and .crt suffixes.


Remediation

Install security update from vendor's website.

Sources