CVE-2025-13698 Details
Description
Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Deciso OPNsense. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of backup configuration files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of root. Was ZDI-CAN-28133.
A directory traversal vulnerability has been identified in the Deciso OPNsense web interface, specifically in the diag_backup.php file. This vulnerability allows authenticated, network-adjacent attackers to create arbitrary files on the affected system. The issue arises from inadequate validation of user-supplied paths before they are used in file operations, particularly in the management of backup configuration files. As a result, attackers can exploit this flaw to generate files with root-level privileges.
Deciso has released a patch for this vulnerability. Users are advised to update to the latest version of OPNsense. Details about the update can be found in the OPNsense GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 23, 2025CISA-ADP
Assessed Dec 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/opnsense/core/commit/cb15c935137d05c86a1e6cf12af877e9c32a23af | [email protected] | Source CodeVendor |
| https://www.zerodayinitiative.com/advisories/ZDI-25-1022/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Deciso OPNsense | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 23, 2025 | New CVE Received | [email protected] |
Volerion