Deciso OPNsense Directory Traversal Vulnerability in diag_backup.php Allowing Arbitrary File Creation

Vulnerability

A directory traversal vulnerability has been identified in the Deciso OPNsense web interface, specifically in the diag_backup.php file. This vulnerability allows authenticated, network-adjacent attackers to create arbitrary files on the affected system. The issue arises from inadequate validation of user-supplied paths before they are used in file operations, particularly in the management of backup configuration files. As a result, attackers can exploit this flaw to generate files with root-level privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized file creation in the system, potentially allowing for further exploitation or privilege escalation, given that the files are created with root privileges.

Remediation

Deciso has released a patch for this vulnerability. Users are advised to update to the latest version of OPNsense. Details about the update can be found in the OPNsense GitHub repository.

Added: Dec 23, 2025, 10:52 PM
Updated: Dec 23, 2025, 10:52 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
4.2
remediation
7.7
relevance
1.7
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.