Netgate

Pfsense Ce

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 19.08.2026 19:18:50
  • Zuletzt bearbeitet 19.08.2026 20:17:20

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX re...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 08.05.2026 00:00:00
  • Zuletzt bearbeitet 12.05.2026 13:45:34

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to ad...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 08.05.2026 00:00:00
  • Zuletzt bearbeitet 12.05.2026 20:39:48

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

  • EPSS 3.64%
  • Veröffentlicht 09.09.2025 20:23:44
  • Zuletzt bearbeitet 14.07.2026 23:17:22

In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authent...

  • EPSS 0.85%
  • Veröffentlicht 09.09.2025 20:19:09
  • Zuletzt bearbeitet 14.07.2026 23:17:22

In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authent...

  • EPSS 14.85%
  • Veröffentlicht 09.09.2025 20:14:37
  • Zuletzt bearbeitet 14.07.2026 23:17:21

In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file ...

  • EPSS 15.78%
  • Veröffentlicht 09.09.2025 20:09:50
  • Zuletzt bearbeitet 14.07.2026 23:17:21

In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authent...

  • EPSS 10.5%
  • Veröffentlicht 09.09.2025 20:02:05
  • Zuletzt bearbeitet 10.10.2025 18:47:06

In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be save...

  • EPSS 0.9%
  • Veröffentlicht 09.09.2025 19:59:14
  • Zuletzt bearbeitet 14.07.2026 23:17:21

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be rea...

  • EPSS 1.03%
  • Veröffentlicht 09.09.2025 19:43:30
  • Zuletzt bearbeitet 14.07.2026 23:17:21

In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.