CVE-2026-53581
ntp: write path traversal
CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape the intended directory and force the system to write user-controlled data to any file on the filesystem. Version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core patch the issue.
| CWE | CWE-22 CWE-73 |
| Vendor | opnsense |
| Product | core |
| Published | Sep 8, 2026 |
| Last Updated | Sep 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for opnsense core
Be the first to know when new critical vulnerabilities affecting opnsense core are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
High
Affected Versions
opnsense / core
< 26.1.9 < 26.4_20