
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67858 is an Improper Neutralization of Argument Delimiters (CWE-88) vulnerability in Foomuuri, a firewall management tool, that allows attackers to manipulate the JSON configuration passed to the nft (nftables) command-line utility. Successful exploitation can lead to integrity loss of the firewall configuration or further unspecified impact. The vulnerability affects all Foomuuri versions prior to 0.31. It was disclosed on January 8, 2026, with SUSE as the assigning CNA. The CVSS v4.0 base score is 7.0 (High), assigned by SUSE (Red Hat Advisory, SUSE Bugzilla).
The root cause is improper neutralization of argument delimiters (CWE-88) when Foomuuri processes JSON configuration data and passes it to the nft command. An attacker can craft malicious JSON input containing argument delimiters that are not properly sanitized, causing nft to interpret injected arguments as legitimate command parameters. The attack vector is local (AV:L), requires no privileges (PR:N), no user interaction (UI:N), and has no special attack requirements, making it straightforward to exploit for any local user who can influence the JSON configuration. The OpenSUSE security team published a technical advisory describing the issue in the context of missing D-Bus authorization controls in Foomuuri (OpenSUSE Security, oss-sec).
Successful exploitation primarily impacts the integrity of the firewall configuration (rated HIGH integrity impact), potentially allowing an attacker to weaken or disable firewall rules, enabling unauthorized network access or bypassing security controls. There is also a low-level confidentiality impact (e.g., reading configuration data) and low availability impact. Because firewall integrity is compromised, exploitation could serve as a stepping stone for further attacks, including lateral movement within a network or exposure of otherwise protected services (Red Hat Advisory, OpenSUSE Security).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. Detection plugins have been published by Tenable Nessus (plugin IDs 282528 and 291268), enabling automated scanning for vulnerable systems (Red Hat Advisory, Feedly).
rpm -q foomuuri or dpkg -l foomuuri).nft arguments via unsanitized JSON fields).nft command without proper sanitization.nft arguments execute with the privileges of the Foomuuri service, allowing the attacker to add, remove, or modify firewall rules — for example, opening ports, disabling filtering chains, or flushing rulesets.nft command invocations in system logs (/var/log/syslog, journalctl) with unusual or extra arguments not matching normal Foomuuri operation; D-Bus activity logs showing unauthorized calls to Foomuuri's D-Bus interface./etc/nftables.conf or related directories.nft list ruleset; unexpected inbound or outbound connections to previously blocked addresses.nft process invocations spawned by the Foomuuri service with anomalous argument strings visible in process listings (ps aux | grep nft) (OpenSUSE Security).The primary remediation is to upgrade Foomuuri to version 0.31 or later, which addresses this argument injection vulnerability. If immediate patching is not possible, restrict local access to systems running vulnerable Foomuuri versions, limit D-Bus access to the Foomuuri service to trusted users only, and monitor firewall configuration files for unauthorized modifications. Implement input validation and sanitization for any JSON configuration data passed to nft. Patches have been distributed for Debian (DSA-6095-1), Fedora 42, and Ubuntu (USN-8326-1) (Red Hat Advisory, OpenSUSE Security, SUSE Bugzilla).
The OpenSUSE security team published a detailed advisory on January 7, 2026, describing the Foomuuri D-Bus authorization and argument injection issues, which was subsequently discussed on the oss-sec mailing list. Security news outlet SecurityOnline.info covered the vulnerabilities under the headline "Wide Open Firewall: Critical Foomuuri Flaws Let Local Users Take Control." The vulnerability received coverage from Linux-focused security outlets including LinuxSecurity.com and Pro-Linux.de, and was noted in the openSUSE planet roundup. Community reaction was moderate, reflecting the niche but security-critical nature of firewall management software (OpenSUSE Security, oss-sec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."