PT-2026-8244 · Opnsense · Opnsense

Ozer Goker

·

Published

2026-02-15

·

Updated

2026-02-15

·

CVE-2019-25372

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPNsense version 19.1
Description The software contains a reflected cross-site scripting issue that allows unauthenticated attackers to inject malicious scripts. This is due to insufficient input validation in the host parameter. Attackers can submit crafted payloads through POST requests to the /diag traceroute.php API endpoint to execute arbitrary JavaScript in the context of a user's browser session. The vulnerable parameter is host.
Recommendations Apply input validation to the host parameter in the /diag traceroute.php API endpoint.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25372

Affected Products

Opnsense