Critical severity9.8NVD Advisory· Published Dec 20, 2022· Updated Jun 17, 2026
CVE-2022-40624
CVE-2022-40624
Description
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:pfsense:pfblockerng:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:pfsense:pfblockerng:*:*:*:*:*:*:*:*range: <2.1.4_27
- (no CPE)range: <=2.1.4_27
- pfSense/pfBlockerNGdescription
Patches
Vulnerability mechanics
References
1- docs.netgate.com/pfsense/en/latest/packages/pfblocker.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.