Cross-site scripting in OPNsense - #VU142550
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in a victim\'s browser.
The vulnerability exists due to cross-site scripting in the wireless EAP selectors on interfaces.php when rendering certificate and CA descriptions. A remote privileged user can inject crafted HTML or script into the descr field to execute arbitrary script code in a victim\'s browser.
User interaction is required to load the wireless interface configuration page where the unescaped descriptions are rendered.