VYPR
High severity8.8NVD Advisory· Published Oct 28, 2025· Updated Jun 17, 2026

CVE-2025-34312

CVE-2025-34312

Description

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist. When a blacklist is installed the application issues an HTTP POST to /cgi-bin/urlfilter.cgi and interpolates the value of BE_NAME directly into a shell invocation without appropriate sanitation. Crafted input can inject shell metacharacters, leading to arbitrary command execution in the context of the 'nobody' user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

18
  • Ipfire/Ipfirellm-fuzzy17 versions
    <2.29 (Core Update 198)+ 16 more
    • (no CPE)range: <2.29 (Core Update 198)
    • cpe:2.3:a:ipfire:ipfire:*:*:*:*:*:*:*:*range: <2.29
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update183:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update184:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update185:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update186:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update187:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update188:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update189:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update190:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update191:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update192:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update193:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update194:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update195:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update196:*:*:*:*:*:*
    • cpe:2.3:a:ipfire:ipfire:2.29:core_update197:*:*:*:*:*:*
  • IPFire.org/IPFirev5
    Range: 0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.