Impact
A logic flaw in OPNsense’s lockout_handler allows an unauthenticated attacker to reset the authentication failure counter for their IP address. By inserting a crafted username that contains a success keyword such as "Accepted" or "Successful login" between normal brute‑force attempts, the system mistakenly treats the login attempt as successful, preventing the counter from ever reaching the lockout threshold. As a result, an attacker can continue to send credentials indefinitely, potentially discovering valid credentials over time.
Affected Systems
The vulnerability impacts all OPNsense core installations older than version 26.1.7. The affected component is the lockout_handler responsible for tracking authentication failures. Users running versions prior to 26.1.7 should be aware that the logic flaw exists in the core package.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability is classified as moderate severity. No EPSS score is available and the issue is not listed in CISA’s KEV catalog. The attack vector is an unauthenticated remote attacker able to send crafted authentication requests over the network; no privileged access is required. Because the flaw is already fixed in 26.1.7, the risk is effectively mitigated once the system is updated.
OpenCVE Enrichment