PT-2025-40279 · Deciso · Opnsense
Alex Williams
·
Published
2025-10-01
·
Updated
2025-10-02
·
CVE-2025-34182
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Deciso OPNsense versions prior to 25.7.4
Description
OPNsense versions prior to 25.7.4 are susceptible to a stored cross-site scripting issue. This occurs when creating a "Interfaces: Devices: Point-to-Point" entry, where the
ptpid parameter is not properly sanitized to remove HTML-related characters or strings. The unsanitized value is then displayed on the /interfaces assign.php page. An attacker with at least "Interfaces: PPPs: Edit" permission can exploit this to inject malicious scripts. The issue was addressed by ensuring proper escaping of form data.Recommendations
Upgrade to OPNsense version 25.7.4 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opnsense