VYPR

Vendor CVEs

Netgate

All CVEs

73 total · sorted by risk
  • CVE-2023-27100CriMar 22, 2023
    risk 0.67cvss 9.8epss 0.10

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

  • CVE-2021-41282HigMar 1, 2022
    risk 0.67cvss 8.8epss 0.87

    diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the…

  • CVE-2019-16667HigSep 26, 2019
    risk 0.65cvss 8.8epss 0.55

    diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.

  • CVE-2025-69691CriMay 8, 2026
    risk 0.64cvss 9.9epss 0.01

    Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

  • CVE-2023-42326HigNov 14, 2023
    risk 0.62cvss 8.8epss 0.64

    An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

  • CVE-2023-27253HigMar 17, 2023
    risk 0.60cvss 8.8epss 0.90

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

  • CVE-2025-69690CriMay 8, 2026
    risk 0.59cvss 9.1epss 0.01

    Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are…

  • CVE-2024-54780HigMay 14, 2025
    risk 0.58cvss 8.8epss 0.12

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this…

  • CVE-2022-26019HigMar 31, 2022
    risk 0.58cvss 8.8epss 0.04

    Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file…

  • CVE-2018-16055HigSep 26, 2018
    risk 0.58cvss 8.8epss 0.11

    An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of the variables. This…

  • CVE-2022-24299HigMar 31, 2022
    risk 0.57cvss 8.8epss 0.02

    Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary…

  • CVE-2019-16915CriSep 26, 2019
    risk 0.57cvss 9.8epss 0.04

    An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

  • CVE-2019-16701HigSep 25, 2019
    risk 0.55cvss 8.8epss 0.20

    pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.

  • CVE-2018-4021HigDec 3, 2018
    risk 0.53cvss 7.2epss 0.72

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to…

  • CVE-2025-12490HigNov 6, 2025
    risk 0.52cvss 8.8epss 0.20

    Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2016-20058HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.01

    Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger…

  • CVE-2016-20057HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.01

    NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and…

  • CVE-2019-25271HigFeb 5, 2026
    risk 0.51cvss 7.8epss 0.00

    NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific…

  • CVE-2018-4020HigDec 3, 2018
    risk 0.51cvss 7.2epss 0.49

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to…

  • CVE-2018-4019HigDec 3, 2018
    risk 0.51cvss 7.2epss 0.49

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to…

  • CVE-2018-20799HigMar 1, 2019
    risk 0.49cvss 7.5epss 0.02

    In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for…

  • CVE-2018-20798HigMar 1, 2019
    risk 0.49cvss 7.5epss 0.01

    The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions.

  • CVE-2019-11816HigMay 20, 2019
    risk 0.47cvss 7.2epss 0.03

    Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.

  • CVE-2022-29273MedFeb 22, 2023
    risk 0.44cvss 6.1epss 0.60

    pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

  • CVE-2025-34175MedSep 9, 2025
    risk 0.41cvss 6.1epss 0.16

    In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated.

  • CVE-2025-34172MedSep 9, 2025
    risk 0.40cvss 6.1epss 0.01

    In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.

  • CVE-2023-42327MedNov 14, 2023
    risk 0.40cvss 5.4epss 0.55

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

  • CVE-2023-42325MedNov 14, 2023
    risk 0.40cvss 5.4epss 0.58

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.

  • CVE-2021-20729MedMar 31, 2022
    risk 0.40cvss 6.1epss 0.03

    Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.

  • CVE-2019-12949MedJun 25, 2019
    risk 0.40cvss 6.1epss 0.03

    In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a…

  • CVE-2023-48795MedDec 18, 2023
    risk 0.39cvss 5.9epss 0.93

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently…

  • CVE-2024-46538MedOct 22, 2024
    risk 0.37cvss 4.8epss 0.82

    A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.

  • CVE-2025-34178MedSep 9, 2025
    risk 0.35cvss 5.4epss 0.04

    In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg…

  • CVE-2025-34177MedSep 9, 2025
    risk 0.35cvss 5.4epss 0.01

    In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg…

  • CVE-2024-57273MedMay 14, 2025
    risk 0.35cvss 5.4epss 0.01

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive…

  • CVE-2024-54779MedMay 14, 2025
    risk 0.35cvss 5.4epss 0.05

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

  • CVE-2020-19203MedJul 12, 2021
    risk 0.35cvss 5.4epss 0.01

    An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget did not encode the descr (description) parameter of wake-on-LAN entries in its…

  • CVE-2020-19201MedJul 12, 2021
    risk 0.35cvss 5.4epss 0.03

    A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the…

  • CVE-2025-53392MedJun 28, 2025
    risk 0.33cvss 5.0epss 0.02

    In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators…

  • CVE-2019-16914MedSep 26, 2019
    risk 0.33cvss 6.1epss 0.02

    An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.

  • CVE-2025-34176MedSep 9, 2025
    risk 0.29cvss 4.3epss 0.15

    In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server…

  • CVE-2025-34173MedSep 9, 2025
    risk 0.28cvss 4.3epss 0.01

    In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals…

  • CVE-2022-31814CriSep 5, 2022
    risk 0.10cvss 9.8epss 0.88

    pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

  • CVE-2019-12347MedMay 29, 2019
    risk 0.08cvss 6.1epss 0.59

    In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.

  • CVE-2015-2295Apr 10, 2015
    risk 0.08cvss epss 0.66

    Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter.

  • CVE-2019-8953MedFeb 20, 2019
    risk 0.07cvss 6.1epss 0.52

    The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.

  • CVE-2017-1000479HigJan 3, 2018
    risk 0.06cvss 8.8epss 0.33

    pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork…

  • CVE-2023-48123HigDec 6, 2023
    risk 0.05cvss 8.8epss 0.68

    An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

  • CVE-2020-11457MedApr 1, 2020
    risk 0.04cvss 5.4epss 0.09

    pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

  • CVE-2014-4688Jul 2, 2014
    risk 0.04cvss epss 0.07

    pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias action, (2) the smartmonemail value to diag_smart.php, or (3) the database value to status_rrd_graph_img.php.

Page 1 of 2