Live data from Hacker News

Chasing the OPNsense RCE: The Story Behind My First CVEs

hackerask.com

1–4 of 4 posts

Re: Chasing the OPNsense RCE: The Story Behind My First CVEs

#4
For those wondering this gives full system compromise to an authenticated user with permissions to edit the firewall, AIUI.

Nasty but I was expecting a remote unauthenticated attack at 9.9. Hopefully you don't allow admin on WAN!

Thanks for finding the bugs and writing about the design pattern problem, HackerAsk.