Description
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape the intended directory and force the system to write user-controlled data to any file on the filesystem. Version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core patch the issue.
Published: 2026-09-08
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file overwrite with root privileges
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a path traversal flaw in the NTP configuration module of the OPNsense firewall platform. By manipulating the GPS or PPS serial port parameter, an attacker who can reach the NTP configuration interface can cause the system to write data outside the intended directory. This permits overwriting any file on the filesystem with root privileges, enabling full compromise of the device.

Affected Systems

OPNsense core through versions before 26.1.9 and the BE branch before 26.4_20 are vulnerable. All firmware builds of OPNsense released before these version thresholds on FreeBSD-based systems are affected.

Risk and Exploitability

With a CVSS score of 9 the vulnerability is rated critical. The EPSS score is not available, and it is not listed in CISA KEV. Because writing arbitrary files requires access to the NTP configuration, the principal attacker is an internal or remote attacker who has authentication or privileged access to the NTP settings. If exploited, the attacker can replace configuration files, create malicious binaries, or otherwise modify critical system components, thereby gaining full control over the device.

Generated by OpenCVE AI on September 9, 2026 at 08:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest OPNsense core update (26.1.9 or later) and BE/opnsense/core update (26.4_20 or later).
  • Limit NTP configuration access to trusted administrators or specific secure networks to reduce the likelihood of exploitation.
  • Implement file integrity monitoring on critical system files to detect unauthorized modifications, and review logs for unexpected NTP configuration changes.

Generated by OpenCVE AI on September 9, 2026 at 08:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Opnsense
Opnsense core
Vendors & Products Opnsense
Opnsense core

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape the intended directory and force the system to write user-controlled data to any file on the filesystem. Version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core patch the issue.
Title ntp: write path traversal
Weaknesses CWE-22
CWE-73
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:37:23.831Z

Reserved: 2026-06-09T19:11:53.484Z

Link: CVE-2026-53581

cve-icon Vulnrichment

Updated: 2026-09-09T13:37:03.790Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T23:17:24.550

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-53581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:00:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path