CVE-2026-45158 Details
Description
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8.
A remote code execution vulnerability has been identified in OPNsense versions prior to 26.1.8. The issue arises from unsanitized user input being passed to the DHCP configuration of the affected interface. This input is processed by a shell script, allowing for execution of arbitrary code as root on the underlying operating system. The vulnerability is present in the web UI, where users with 'page-interfaces' privileges can configure interfaces to use DHCP on IPv4. By setting a hostname that includes malicious payloads, the crafted input is executed when the DHCP client script is processed.
Users should upgrade to OPNsense version 26.1.8 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/opnsense/core/security/advisories/GHSA-5rx3-w735-74wm | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opnsense opnsense | < 26.1.8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 13, 2026 | New CVE Received | [email protected] |