PatchSiren cyber security CVE debrief
CVE-2026-45255 FreeBSD CVE debrief
CVE-2026-45255 is a command-injection flaw in FreeBSD's bsdinstall and bsdconfig Wi‑Fi scan flow. When these tools build a menu of nearby networks, a shell script handles network names unsafely, allowing a specially crafted SSID to trigger subshell command execution as root. The attacker must be within Wi‑Fi range, and the flaw is exposed as soon as the scan prompt is shown, even if the malicious network is never selected.
- Vendor
- FreeBSD
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-07-23
Who should care
FreeBSD administrators, operators of systems using bsdinstall or bsdconfig, and anyone who runs installation or configuration workflows near untrusted Wi‑Fi networks should treat this as a priority issue.
Technical summary
The issue is a shell-injection weakness in the Wi‑Fi network selection path used by bsdinstall and bsdconfig. Network names are collected into a list and passed through bsddialog-driven shell logic without sufficient protection against shell expansion, which can let a crafted access point name execute commands via a subshell. NVD lists the weakness as CWE-78 (OS Command Injection), and the advisory description indicates the result can be root-level code execution.
Defensive priority
High: the impact is root-level code execution, but exploitation requires proximity to a crafted access point and use of the affected scan prompt.
Recommended defensive actions
- Apply the vendor fix or update once the FreeBSD advisory or your distribution package notes provide a patched build.
- Avoid scanning for nearby Wi‑Fi networks from bsdinstall or bsdconfig in untrusted RF environments until patched.
- Prefer wired or otherwise trusted network setup paths for installation and configuration workflows.
- Track the FreeBSD security advisory referenced by NVD for any follow-on guidance or affected-release details.
Evidence notes
The supplied CVE description states that bsdinstall and bsdconfig use a shell script to handle Wi‑Fi network names and that insufficient escaping allows shell expansion, enabling command execution via a crafted network name. The NVD record supplied in the corpus references the FreeBSD Security Team advisory FreeBSD-SA-26:23.bsdinstall.asc and lists CWE-78 as the weakness. The corpus does not provide affected version ranges or a CVSS score.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45255 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45255
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45255 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45255
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.freebsd.org/advisories/FreeBSD-SA-26:23.bsdinstall.asc
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.