logo

Wide Open Firewall: Critical Foomuuri Flaws Let Local Users Take Control

ID: 5b6a22ed-9a03-52a1-b5b6-bd78c3cdeffb

STIX ID: report--5b6a22ed-9a03-52a1-b5b6-bd78c3cdeffb

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Ddos

...
...

SUSE security researchers discovered two serious local vulnerabilities in Foomuuri: a complete absence of D-Bus client authorization (CVE-2025-67603) permitting any local user to change firewall configuration, and inadequate input validation (CVE-2025-67858) allowing arbitrary strings to be passed as interface names that could enable log spoofing or manipulation of the JSON configuration for nftables; the issues were patched in Foomuuri v0.31.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.