A vulnerability was found in OPNsense 25.1 and classified as critical. The impacted element is an unknown function of the file interfaces_bridge_edit.php. The manipulation of the argument span results in command injection.
This vulnerability is known as CVE-2025-50989. It is possible to launch the attack remotely. No exploit is available.