Impact
The vulnerability is a path traversal flaw in the NTP configuration module of the OPNsense firewall platform. By manipulating the GPS or PPS serial port parameter, an attacker who can reach the NTP configuration interface can cause the system to write data outside the intended directory. This permits overwriting any file on the filesystem with root privileges, enabling full compromise of the device.
Affected Systems
OPNsense core through versions before 26.1.9 and the BE branch before 26.4_20 are vulnerable. All firmware builds of OPNsense released before these version thresholds on FreeBSD-based systems are affected.
Risk and Exploitability
With a CVSS score of 9 the vulnerability is rated critical. The EPSS score is not available, and it is not listed in CISA KEV. Because writing arbitrary files requires access to the NTP configuration, the principal attacker is an internal or remote attacker who has authentication or privileged access to the NTP settings. If exploited, the attacker can replace configuration files, create malicious binaries, or otherwise modify critical system components, thereby gaining full control over the device.
OpenCVE Enrichment