CVE-2023-27152: Opnsense

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

Affected products

Published 2023-10-23. Last modified 2026-06-17.