VYPR
Medium severity4.3NVD Advisory· Published Sep 9, 2025· Updated Jul 14, 2026

CVE-2025-34173

CVE-2025-34173

Description

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: Snort package" permissions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:pfsense:pfsense:*:*:*:*:community:*:*:*
    Range: <2.8.0
  • Netgate/Pfsensellm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 4.1.6_25

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.