CVE-2026-53581
largePath Traversal File Overwrite in OPNsense NTP Configuration Module
OPNsense, a FreeBSD-based firewall and routing platform, contains a path traversal vulnerability in its NTP configuration module in versions of opnsense/core prior to 26.1.9 and BE/opnsense/core prior to 26.4_20. An attacker who already has access to the NTP configuration (e.g., an administrator or delegated account with rights to change NTP settings) can manipulate the GPS or PPS serial port parameter to escape the intended directory. This forces the system to write user-controlled data to any file on the filesystem as the root user, enabling arbitrary file overwrites and potentially full root-level compromise of the firewall (CVSS 3.1 score 9.0, critical). All OPNsense deployments running affected core versions are impacted, though exploitation requires privileged access to the NTP configuration rather than anonymous access. No public proof-of-concept or in-the-wild exploitation is currently known; EPSS is low at 0.3% (25th percentile) and the issue is not in CISA KEV.
What to do: Upgrade Community Edition to opnsense/core 26.1.9 or later, or Business Edition to BE/opnsense/core 26.4_20 or later. Until patched, restrict access to the NTP configuration pages to trusted administrators only and avoid exposing the OPNsense web UI directly to the internet. Review current GPS/PPS serial port settings and check for unexpected or recently modified system files that could indicate tampering.
| OPNsense (Deciso) opnsense/core (Community Edition) | prior to 26.1.9 |
| OPNsense (Deciso) BE/opnsense/core (Business Edition) | prior to 26.4_20 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape the intended directory and force the system to write user-controlled data to any file on the filesystem. Version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core patch the issue.
- Weakness
- CWE-22, CWE-73
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.