CVE-2019-25377

OPNsense 19.1 contains a reflected cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject malicious scripts via the value parameter. Attackers can craft POST requests with script payloads in the value parameter to execute JavaScript in the context of authenticated user sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opnsense:opnsense:19.1:*:*:*:*:*:*:*

History

18 Feb 2026, 19:08

Type Values Removed Values Added
CPE cpe:2.3:a:opnsense:opnsense:19.1:*:*:*:*:*:*:*
First Time Opnsense opnsense
Opnsense
References () https://forum.opnsense.org/index.php?topic=11469.0 - () https://forum.opnsense.org/index.php?topic=11469.0 - Release Notes
References () https://opnsense.org - () https://opnsense.org - Product
References () https://www.exploit-db.com/exploits/46351 - () https://www.exploit-db.com/exploits/46351 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-systemadvancedsysctlphp - () https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-systemadvancedsysctlphp - Broken Link

18 Feb 2026, 17:52

Type Values Removed Values Added
Summary
  • (es) OPNsense 19.1 contiene una vulnerabilidad de cross-site scripting reflejado en el endpoint system_advanced_sysctl.php que permite a los atacantes inyectar scripts maliciosos a través del parámetro value. Los atacantes pueden elaborar solicitudes POST con cargas útiles de script en el parámetro value para ejecutar JavaScript en el contexto de sesiones de usuario autenticadas.

15 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-15 14:16

Updated : 2026-02-18 19:08


NVD link : CVE-2019-25377

Mitre link : CVE-2019-25377

CVE.ORG link : CVE-2019-25377


JSON object : View

Products Affected

opnsense

  • opnsense
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')