CVE-2026-45158: OPNsense: Command Injection via Attacker-Controlled DHCP Config
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45158?
CVE-2026-45158 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-45158?
To mitigate CVE-2026-45158, upgrade your OPNsense to version 26.1.8 or later.
What are the potential impacts of CVE-2026-45158?
The impacts of CVE-2026-45158 include unauthorized access and control over the affected OPNsense device.
Who is affected by CVE-2026-45158?
CVE-2026-45158 affects users of OPNsense versions prior to 26.1.8.
How does CVE-2026-45158 work?
CVE-2026-45158 works by allowing an attacker to inject malicious commands into the DHCP configuration, leading to arbitrary code execution.