Executive brief
FreeBSD's installation and configuration tools are vulnerable to a security flaw that allows an attacker to take full control of a system. By creating a Wi-Fi network with a specially crafted name, an attacker within physical range can execute malicious commands with administrative (root) privileges. This occurs automatically when a user searches for nearby Wi-Fi networks during setup, even if they do not attempt to connect to the attacker's network.
Technical details
A command injection vulnerability exists in the FreeBSD bsdinstall and bsdconfig utilities due to improper neutralization of shell special elements in Wi-Fi network names. The utilities use a shell script to process scan results and pass them to bsddialog(1) without adequate escaping, allowing for shell expansion and subshell execution. An attacker within Wi-Fi range can broadcast a crafted SSID that, when scanned by the victim, executes arbitrary commands as the root user. The vulnerability is triggered during the scanning phase; no user interaction beyond initiating the scan is required. Patches have been released for FreeBSD 14 and 15 branches.
Affected products
- FreeBSD Project FreeBSD All supported versions prior to correction date 2026-05-20
Timeline
- 2026-05-20: patched: Fixes committed to stable and release branches.
- 2026-05-20: advisory: FreeBSD-SA-26:23.bsdinstall published.
- 2026-05-21: disclosed: CVE-2026-45255 published.