ZeroHour

Vulnerabilities

40 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-20058
Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local att

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.

NVD description · AI analysis pending
8.5<1% PoC
  • netgate amiti antivirus
CVE-2016-20057
NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privi

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.

NVD description · AI analysis pending
8.5<1% PoC
  • netgate registry cleaner
CVE-2024-54780
+2 in the same advisory: …54779 …57273
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitiz

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.

NVD description · AI analysis pending
8.8
group max
12% PoC
  • netgate pfsense ce
  • netgate pfsense plus
CVE-2024-46538
Cross-Site Scripting (XSS) in pfSense interfaces_groups_edit.php

pfSense 2.5.2 contains a cross-site scripting flaw (CWE-79) in the web UI script interfaces_groups_edit.php, where a crafted payload injected into the $pconfig parameter is rendered without proper sanitization. An attacker who can submit the crafted input — the CVSS vector requires highly privileged (admin-level) access — can cause arbitrary web scripts or HTML to execute in the browser of a user viewing the affected page. Successful execution in an administrator's session could allow session hijacking, unauthorized configuration changes, or theft of credentials, with scope changed (S:C) meaning the script can cross the security boundary of the vulnerable component. Affected users are administrators and organizations running pfSense 2.5.2 from Netgate. Exploitation has not been confirmed in the wild and the flaw is not in CISA KEV, but a public proof of concept exists and EPSS puts the 30-day exploitation probability at 81.6% (top percentile), so exploitation activity is considered likely.

Do: Organizations running pfSense 2.5.2 should upgrade to the latest pfSense release available from Netgate and verify the fixed version in Netgate's advisories, since the CVE data does not specify one. Until then, restrict web UI access to trusted management networks or VPN, limit the number of admin accounts (exploitation requires admin-level privileges), and inspect saved interface group configuration for unexpected injected HTML or script content. Check access logs for requests to interfaces_groups_edit.php as an indicator of probing.

4.882% PoC
  • Netgate pfSense 2.5.2 (as reported in the CVE; the data does not confirm which other versions are affected or the fixed version)
largetens of thousands of internet-exposed pfSense web UIs (installs still on the 2.5.2 line are a subset)
CVE-2023-48123
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the pac

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

NVD description · AI analysis pending
8.868%
  • netgate pfsense
  • netgate pfsense plus
CVE-2023-42326
+2 in the same advisory: …42325 …42327
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_e

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

NVD description · AI analysis pending
8.8
group max
64%
  • netgate pfsense
  • netgate pfsense plus
CVE-2020-21487
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field o

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.

NVD description · AI analysis pending
9.6<1%
  • netgate pfsense
  • netgate pfsense acme package
CVE-2023-27100
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 all

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

NVD description · AI analysis pending
9.810%
  • netgate pfsense plus
  • netgate pfsense
CVE-2023-27253
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via m

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

NVD description · AI analysis pending
8.890%
  • netgate pfsense
CVE-2022-29273
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

NVD description · AI analysis pending
6.160%
  • netgate pfsense
CVE-2020-21219
Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code vi

Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.

NVD description · AI analysis pending
6.1<1%
  • netgate acme
  • netgate pfsense
CVE-2022-31814
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header.

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

NVD description · AI analysis pending
9.892% PoC ×2
  • netgate pfblockerng
CVE-2022-26019
+1 in the same advisory: …24299
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22

Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.

NVD description · AI analysis pending
8.84%
  • netgate pfsense
  • netgate pfsense plus
CVE-2021-20729
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and

Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.

NVD description · AI analysis pending
6.13%
  • netgate pfsense plus
  • netgate pfsense
CVE-2020-19201
+1 in the same advisory: …19203
A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4

A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the descr (description) parameter on NAT rules.

NVD description · AI analysis pending
5.43% PoC
  • netgate pfsense
CVE-2020-10797
An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version.

An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.

NVD description · AI analysis pending
6.12%
  • netgate pfsense
CVE-2020-11457
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

NVD description · AI analysis pending
5.49%
  • netgate pfsense
CVE-2019-16915
+2 in the same advisory: …16667 …16914
An issue was discovered in pfSense through 2.4.4-p3.

An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

NVD description · AI analysis pending
9.8
group max
4%
  • netgate pfsense
CVE-2019-16701
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters i

pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.

NVD description · AI analysis pending
8.820% PoC ×2
  • netgate pfsense
CVE-2019-12949
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can levera

In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run any command with root privileges on that server.

NVD description · AI analysis pending
6.13% PoC
  • netgate pfsense
CVE-2019-12585
+1 in the same advisory: …12584
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

NVD description · AI analysis pending
9.8
group max
5%
  • apcupsd apcupsd
  • apcupsd pfsense
CVE-2019-12347
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php actio

In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.

NVD description · AI analysis pending
6.159% PoC ×3
  • netgate pfsense
CVE-2019-11816
Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to

Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.

NVD description · AI analysis pending
7.23%
  • netgate pfsense
  • netgate opnsense
CVE-2018-20799
+1 in the same advisory: …20798
In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basi

In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for attackers to bypass intended access restrictions.

NVD description · AI analysis pending
7.52% PoC
  • netgate pfsense
CVE-2019-8953
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and hapro

The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.

NVD description · AI analysis pending
6.152% PoC ×2
  • netgate haproxy
CVE-2018-4021
+2 in the same advisory: …4020 …4019
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request.

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_battery_mode` POST parameter.

NVD description · AI analysis pending
7.272% PoC
  • netgate pfsense
CVE-2018-16055
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user inp

An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of the variables. This allows an authenticated WebGUI user with privileges for the affected page to execute commands in the context of the root user when submitting a request to relinquish a DHCP lease for an interface which is configured to obtain its address via DHCP.

NVD description · AI analysis pending
8.811%
  • netgate pfsense
CVE-2017-1000479
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the

pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from the code during an internal security audit under "possibly insecure" suspicions.

NVD description · AI analysis pending
8.833% PoC ×2
  • netgate pfsense
  • netgate opnsense