CVE-2023-39001 | OPNsense up to 23.6 Backup Configuration File diag_backup.php command injection (EUVD-2023-42758)
A vulnerability identified as critical has been detected in OPNsense up to 23.6. This vulnerability affects unknown code of the file diag_backup.php of the component Backup Configuration File Handler. Performing a manipulation results in command injection.
This vulnerability is cataloged as CVE-2023-39001. The attack must originate from the local network. There is no exploit available.
You should upgrade the affected component.