{"id":8271,"date":"2025-11-07T10:05:20","date_gmt":"2025-11-07T10:05:20","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/07\/freebsd-based-opnsense-firewall-released-for-security-issues-and-improvements\/"},"modified":"2025-11-07T10:05:20","modified_gmt":"2025-11-07T10:05:20","slug":"freebsd-based-opnsense-firewall-released-for-security-issues-and-improvements","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/07\/freebsd-based-opnsense-firewall-released-for-security-issues-and-improvements\/","title":{"rendered":"FreeBSD-based OPNsense Firewall Released for Security Issues and Improvements"},"content":{"rendered":"<p>    FreeBSD-based OPNsense Firewall Released for Security Issues and Improvements<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>OPNsense has released an update focused on eliminating security vulnerabilities and improving firewall performance.<\/p>\n<p>The latest version includes third-party security updates, <a href=\"https:\/\/cybersecuritynews.com\/sonicwall-confirms-firewall-backup-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">firewall<\/a> improvements, and fixes that make the system more reliable for network administrators and security professionals.<\/p>\n<p>The development team has made eliminating unsafe shell usage a primary focus. This is important because shell execution has historically been the source of multiple security problems in the project.<\/p>\n<p>These changes strengthen the firewall\u2019s overall security posture. By removing unsafe shell commands from the backend, OPNsense reduces the risk of attackers exploiting these vulnerabilities.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-addressing-security-concerns-through-code-improvements\"><strong>Addressing Security Concerns Through Code Improvements<\/strong><\/h2>\n<p>A security researcher at Pellera Technologies, working with the Trend<a href=\"https:\/\/cybersecuritynews.com\/34-0-day-vulnerabilities-pwn2own\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Zero Day <\/a>Initiative, reported an issue that helped guide these improvements.<\/p>\n<p>The update also includes securing execution commands in recovery scripts and implementing safer file handling through the file_safe() function across various system components.<\/p>\n<p>Based on user feedback from the previous 25.7.6 release, the team has significantly improved the firewall live log feature.<\/p>\n<p>These improvements include faster data rendering, optimized view buffering, and fixed data ordering issues.<\/p>\n<p>The system now prevents unnecessary repeated host lookups, speeding up the display of logged<a href=\"https:\/\/cybersecuritynews.com\/linux-malware-network-traffic-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\"> network traffic <\/a>for administrators monitoring it in real time.<\/p>\n<p>Additional performance enhancements include improved grid responsiveness in the user interface and better keyboard shortcuts for advanced settings and help sections.<\/p>\n<p>The OPNsense team continues prioritizing security and stability for network protection. The <a href=\"https:\/\/forum.opnsense.org\/index.php?topic=49616.0\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">release<\/a> includes updated versions of essential security tools.<\/p>\n<p>Suricata has been upgraded to version 8.0.2 for improved intrusion detection capabilities, while Unbound reaches version 1.24.1 for enhanced <a href=\"https:\/\/cybersecuritynews.com\/dns-queries-exploited-for-c2\/\" target=\"_blank\" rel=\"noreferrer noopener\">DNS security<\/a>.<\/p>\n<p>PHP, SQLite, and StrongSwan have also received security updates to maintain system integrity.<\/p>\n<p>The team is working on several exciting features coming to version 25.7.x, including a neighbor watch daemon for network monitoring, a new NDP proxy plugin for <a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-ipv6-stateless-address-for-aitm-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">IPv6 networks<\/a>, and a community-created theme option.<\/p>\n<p>A hotfix release was also issued to address a high-availability synchronization issue in specific edge cases, ensuring smoother deployments for users running multiple firewalls in failover configurations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/freebsd-based-opnsense-firewall\/\">FreeBSD-based OPNsense Firewall Released for Security Issues and Improvements<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/freebsd-based-opnsense-firewall\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FreeBSD-based OPNsense Firewall Released for Security Issues and Improvements OPNsense has released an update focused on eliminating security vulnerabilities and improving firewall performance. The latest version includes third-party security updates, firewall improvements, and fixes that make the system more reliable for network administrators and security professionals. The development team has made eliminating unsafe shell usage [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,724],"tags":[130],"class_list":["post-8271","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-firewall","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8271"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8271"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8271\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8271"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8271"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8271"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}