A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition prior to 23.7 and Business Edition prior to 23.4.2 allows malicious users to execute arbitrary commands via a crafted backup configuration file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
opnsense opnsense |