Wide Open Firewall: Critical Foomuuri Flaws Let Local Users Take Control
ID: 5b6a22ed-9a03-52a1-b5b6-bd78c3cdeffb
STIX ID: report--5b6a22ed-9a03-52a1-b5b6-bd78c3cdeffb
Feed Name: securityonline.info
Threat Score
SUSE security researchers discovered two serious local vulnerabilities in Foomuuri: a complete absence of D-Bus client authorization (CVE-2025-67603) permitting any local user to change firewall configuration, and inadequate input validation (CVE-2025-67858) allowing arbitrary strings to be passed as interface names that could enable log spoofing or manipulation of the JSON configuration for nftables; the issues were patched in Foomuuri v0.31.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
