MEDIUM
OPNsense 19.1 Reflected XSS via vpn_ipsec_settings.php
Published Feb 15, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.34%
Description
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting the passthrough_networks parameter in vpn_ipsec_settings.php. Attackers can craft POST requests with JavaScript payloads in the passthrough_networks parameter to execute arbitrary code in users' browsers.
Affected products
-
- Version 19.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
OPNsense 19.1.1 released
Weaknesses (1)
References (4)
- https://forum.opnsense.org/index.php?topic=11469.0 patchRelease Notes
- https://opnsense.org product
- https://www.exploit-db.com/exploits/46351 exploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-vpnipsecsettingsphp third-party-advisoryBroken Link
| Link | Providers | Tags |
|---|---|---|
| https://forum.opnsense.org/index.php?topic=11469.0 | patchRelease Notes | |
| https://opnsense.org | product | |
| https://www.exploit-db.com/exploits/46351 | exploitThird Party AdvisoryVDB Entry | |
| https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-vpnipsecsettingsphp | third-party-advisoryBroken Link |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Feb 15, 2026
Updated May 24, 2026
Reserved Feb 15, 2026
Link CVE-2019-25374
CISA Vulnrichment
Updated Feb 17, 2026