{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-45255", "assignerOrgId": "63664ac6-956c-4cba-a5d0-f46076e16109", "state": "PUBLISHED", "assignerShortName": "freebsd", "dateReserved": "2026-05-11T16:27:44.891Z", "datePublished": "2026-05-21T09:27:20.431Z", "dateUpdated": "2026-05-21T09:27:20.431Z"}, "containers": {"cna": {"datePublic": "2026-05-20T23:00:00.000Z", "title": "Remote code execution via installer Wi-Fi access point scans", "references": [{"tags": ["vendor-advisory"], "url": "https://security.freebsd.org/advisories/FreeBSD-SA-26:23.bsdinstall.asc"}], "affected": [{"defaultStatus": "unknown", "modules": ["bsdinstall"], "product": "FreeBSD", "vendor": "FreeBSD", "versions": [{"status": "affected", "versionType": "release", "version": "15.0-RELEASE", "lessThan": "p9"}, {"status": "affected", "versionType": "release", "version": "14.4-RELEASE", "lessThan": "p5"}, {"status": "affected", "versionType": "release", "version": "14.3-RELEASE", "lessThan": "p14"}]}], "credits": [{"lang": "en", "type": "finder", "value": "Austin Ralls"}], "descriptions": [{"lang": "en", "value": "When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the user to select a network.  This is implemented using a shell script, and the code which handled network names was not careful to prevent expansion by the shell.  As a result, a suitably crafted network name can be used to execute commands via a subshell.\n\nThe problem can be exploited to execute code as root on the system running bsdinstall or bsdconfig.  The attacker would need to create an access point with a specially crafted name and be within range of a Wi-Fi scan.  Note that bsdinstall and bsdconfig are vulnerable as soon as the user prompts them to scan for nearby networks; they do not need to actually select the malicious network."}], "problemTypes": [{"descriptions": [{"cweId": "CWE-78", "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"orgId": "63664ac6-956c-4cba-a5d0-f46076e16109", "shortName": "freebsd", "dateUpdated": "2026-05-21T09:27:20.431Z"}, "x_generator": {"engine": "cvelib 1.8.0"}}}}