PT-2026-8242 · Opnsense · Opnsense

Ozer Goker

·

Published

2026-02-15

·

Updated

2026-02-15

·

CVE-2019-25370

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPNsense version 19.1
Description OPNsense version 19.1 is subject to a reflected cross-site scripting issue. Successful exploitation allows attackers to inject malicious scripts. This is achieved by submitting crafted input through multiple parameters. Specifically, attackers can send POST requests to the ''interfaces vlan edit.php'' endpoint. The tag, descr, and vlanif parameters are vulnerable to script payloads, enabling the execution of arbitrary JavaScript in users' browsers.
Recommendations Apply input validation and output encoding to the tag, descr, and vlanif parameters in the ''interfaces vlan edit.php'' endpoint.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25370

Affected Products

Opnsense