CVE-2025-34182: Deciso OPNsense < 25.7.4 /interfaces_ppps_edit.php ptpid Stored XSS
In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the parameter ptpid is not sanitized of HTML-related characters/strings. This value is directly displayed when visiting the page/interfacesassign.php, which can result in stored cross-site scripting. The attacker must be authenticated with at-least "Interfaces: PPPs: Edit" permission. This vulnerability has been addressed by the vendor in the product release notes as "ui: legacyhtmlescapeformdata() was not escaping keys only data elements."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34182?
CVE-2025-34182 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-34182?
To fix CVE-2025-34182, upgrade to Deciso OPNsense version 25.7.4 or later, which includes the necessary security patches.
What type of vulnerability is CVE-2025-34182?
CVE-2025-34182 is a stored cross-site scripting (XSS) vulnerability that arises from improper parameter sanitization.
What systems are affected by CVE-2025-34182?
CVE-2025-34182 affects Deciso OPNsense versions prior to 25.7.4.
What are the potential impacts of CVE-2025-34182?
The potential impacts of CVE-2025-34182 include the execution of malicious scripts in the context of a user's browser, leading to unauthorized actions or data theft.