Impact
The vulnerability arises from the certificate description field, which is stored without sanitization. An authenticated attacker can insert arbitrary HTML or JavaScript into this field via the trust certificate API. During rendering in the Dashboard Certificates widget, the raw value is directly inserted into HTML attributes and text content, allowing the injected payload to execute in the browsers of other authenticated users that view the Dashboard.
Affected Systems
This flaw exists in OPNsense versions prior to 26.1.9 and affects the Deciso B.V. OPNsense firewall software. The vulnerability is limited to installations that use the trust certificate API and display certificate details in the Dashboard.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the EPSS score is not available. The exploit requires authenticated access to the platform and the ability to write to the certificate description field. Once executed, the malicious script runs in the browsers of any logged‑in user who views the Dashboard, enabling session hijacking or credential theft. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment