PT-2026-7946 · Deciso · Opnsense

Alex Williams

·

Published

2026-02-12

·

Updated

2026-02-20

·

CVE-2026-2035

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Deciso OPNsense (affected versions not specified)
Description A flaw exists in the handling of backup configuration files within Deciso OPNsense. The issue stems from insufficient validation of user-provided input before it is used in a system call, potentially allowing network-adjacent attackers to execute arbitrary code. Successful exploitation requires authentication and results in code execution with root privileges. The vulnerable file is diag backup.php. The vulnerability was identified as ZDI-CAN-28131.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-2035
ZDI-26-078

Affected Products

Opnsense