VYPR
Vendor

DECISO

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2023-27152CriOct 23, 2023
    risk 0.64cvss 9.8epss 0.01

    DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

  • CVE-2025-34182MedOct 1, 2025
    risk 0.33cvss epss 0.00

    In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the parameter ptpid is not sanitized of HTML-related characters/strings. This value is directly displayed when visiting the page/interfaces_assign.php, which can result…

  • CVE-2025-13698MedDec 23, 2025
    risk 0.22cvss 4.5epss 0.01

    Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Deciso OPNsense. Authentication is required to exploit this…