Executive brief
OPNsense is an open-source firewall and routing platform used to secure network traffic. A flaw in its login protection system allows attackers to bypass automatic lockouts by using specially crafted usernames that trick the system into thinking a login was successful. This allows an attacker to perform unlimited password-guessing attacks against the web interface or SSH service without being blocked, potentially leading to unauthorized access to the network's security infrastructure.
Technical details
A logic flaw exists in the OPNsense 'lockout_handler' script, which processes syslog events to manage the 'sshlockout' firewall alias. The handler uses regular expressions to identify both failed and successful logins; however, it processes success patterns (like '.*Accepted.*') by explicitly resetting the failure counter for the source IP. Because the WebGUI logs include the raw username provided by the user, an unauthenticated attacker can submit a login attempt with a username such as 'Accepted'. The handler matches this against the success pattern and clears the attacker's failure count. By alternating between real password guesses and these crafted 'reset' attempts, an attacker can prevent their IP from ever reaching the lockout threshold, enabling indefinite brute-force attacks against the WebGUI and SSH. This is fixed in version 26.1.7 by prioritizing failure patterns over success patterns.
Affected products
- OPNsense OPNsense core < 26.1.7
Timeline
- 2026-04-30: advisory: Original GitHub security advisory published
- 2026-05-13: disclosed: CVE published to NVD