OPNsense 16.1.11 released


 Hi everyone,

We are skipping a bit ahead with 16.1.11 to address a CSRF vulnerability, which shows us the good path we have been on since we started[1] and we will surely continue this security-aware trend.

In other news, this update includes native GeoIP alias support, captive portal voucher customisations requested by many and the last batch of Russian, effectively bringing it to 100% completed. Wow!

Here is the full change log:

  • services: fix CSRF vulnerability in status_services.php[2]
  • dhcp: bring back usage of the authoritative directive
  • system: allow periodic backups of RRD and DHCP for non-MFS
  • captive portal: add option for less secure passwords, password and username length
  • firewall: add GeoIP aliases feature
  • openvpn: status page would not show the correct process status
  • languages: completed Russian translation (contributed by Smart-Soft Ltd.)
  • languages: updated French

Stay safe,
Your OPNsense team


[1] https://forum.opnsense.org/index.php?topic=2837.0
[2] https://cxsecurity.com/issue/WLB-2016040106