OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation in the host parameter. Attackers can submit crafted POST requests to the diag_ping.php endpoint with script payloads in the host parameter to execute arbitrary JavaScript in users' browsers.
Advisories
No advisories yet.
Fixes
Solution
OPNsense 19.1.1 released
Workaround
No workaround given by the vendor.
References
History
Sun, 15 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation in the host parameter. Attackers can submit crafted POST requests to the diag_ping.php endpoint with script payloads in the host parameter to execute arbitrary JavaScript in users' browsers. | |
| Title | OPNsense 19.1 Reflected XSS via diag_ping.php | |
| First Time appeared |
Opnsense
Opnsense opnsense |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opnsense
Opnsense opnsense |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-15T13:58:53.595Z
Reserved: 2026-02-15T13:20:10.666Z
Link: CVE-2019-25371
No data.
Status : Received
Published: 2026-02-15T14:16:06.723
Modified: 2026-02-15T14:16:06.723
Link: CVE-2019-25371
No data.
OpenCVE Enrichment
Updated: 2026-02-16T09:42:58Z
Weaknesses