Chasing the OPNsense RCE: The Story Behind My First CVEs
1–4 of 4 posts
Re: Chasing the OPNsense RCE: The Story Behind My First CVEs
#2[deleted]
Re: Chasing the OPNsense RCE: The Story Behind My First CVEs
#3Why did you not mention LLM use in the post at all?
Are you not using LLMs as part of your toolkit in 2026?
Re: Chasing the OPNsense RCE: The Story Behind My First CVEs
#4For those wondering this gives full system compromise to an authenticated user with permissions to edit the firewall, AIUI.
Nasty but I was expecting a remote unauthenticated attack at 9.9. Hopefully you don't allow admin on WAN!
Thanks for finding the bugs and writing about the design pattern problem, HackerAsk.