High severity8.8NVD Advisory· Published Sep 25, 2019· Updated Jun 17, 2026
CVE-2019-16701
CVE-2019-16701
Description
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:*range: >=2.3.4,<2.4.4
- cpe:2.3:a:netgate:pfsense:2.4.4:-:*:*:*:*:*:*
- cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*
- cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*
- cpe:2.3:a:netgate:pfsense:2.4.4:p3:*:*:*:*:*:*
- pfSense/pfSensedescription
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/154587/pfSense-2.3.4-2.4.4-p3-Remote-Code-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- hackernews.blog/pfsense-2-3-4-2-4-4-p3-remote-code-injection/nvdExploitThird Party Advisory
- github.com/pfsense/pfsense/commits/masternvdThird Party Advisory
News mentions
0No linked articles in our index yet.