OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting the passthrough_networks parameter in vpn_ipsec_settings.php. Attackers can craft POST requests with JavaScript payloads in the passthrough_networks parameter to execute arbitrary code in users' browsers.
Advisories
No advisories yet.
Fixes
Solution
OPNsense 19.1.1 released
Workaround
No workaround given by the vendor.
References
History
Sun, 15 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting the passthrough_networks parameter in vpn_ipsec_settings.php. Attackers can craft POST requests with JavaScript payloads in the passthrough_networks parameter to execute arbitrary code in users' browsers. | |
| Title | OPNsense 19.1 Reflected XSS via vpn_ipsec_settings.php | |
| First Time appeared |
Opnsense
Opnsense opnsense |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opnsense
Opnsense opnsense |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-15T13:58:55.932Z
Reserved: 2026-02-15T13:20:49.623Z
Link: CVE-2019-25374
No data.
Status : Received
Published: 2026-02-15T14:16:07.243
Modified: 2026-02-15T14:16:07.243
Link: CVE-2019-25374
No data.
OpenCVE Enrichment
Updated: 2026-02-16T09:42:54Z
Weaknesses