High severity8.8NVD Advisory· Published Sep 26, 2019· Updated Jun 17, 2026
CVE-2019-16667
CVE-2019-16667
Description
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- pfSense/pfSensedescription
Patches
Vulnerability mechanics
References
2- pastebin.com/TEJdu9LNnvdExploitThird Party Advisory
- packetstormsecurity.com/files/158614/pfSense-2.4.4-p3-Cross-Site-Request-Forgery.htmlnvd
News mentions
0No linked articles in our index yet.