CVE-2026-53581
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in OPNsense NTP Configuration Module

Vulnerability report for CVE-2026-53581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape the intended directory and force the system to write user-controlled data to any file on the filesystem. Version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core patch the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-25
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
opnsense core to 26.1.9 (exc)
be opnsense to 26.4_20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in OPNsense's NTP configuration module. It allows an attacker with NTP configuration access to overwrite any file on the system as the root user by manipulating GPS or PPS serial port parameters. The issue occurs because user input is directly concatenated with /dev/ without validation, enabling filesystem escape.

Detection Guidance

Check OPNsense version with 'opnsense-version' command. If version is below 26.1.9 or 26.4_20, the system is vulnerable. Review NTP configuration files in /usr/local/etc/ntpd.conf and /etc/inc/ntpd.inc for suspicious serial port parameters.

Impact Analysis

An attacker could replace critical system files like SSH keys or config.xml, leading to full system compromise. This grants them complete control over the OPNsense firewall/router, potentially allowing network takeover, data theft, or denial of service.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's integrity/confidentiality requirements and HIPAA's security rules. Full system compromise would likely result in non-compliance with these regulations.

Mitigation Strategies

Upgrade OPNsense to version 26.1.9 or 26.4_20 or later immediately. Restrict access to NTP configuration module to trusted administrators only. Monitor filesystem changes for unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart