Vulnerabilities > Netgate > Pfsense > 2.5.2

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-46538 Cross-site Scripting vulnerability in Netgate Pfsense 2.5.2
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
network
low complexity
netgate CWE-79
4.8
2023-12-06 CVE-2023-48123 Unspecified vulnerability in Netgate Pfsense and Pfsense Plus
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.
network
low complexity
netgate
8.8
2023-11-14 CVE-2023-42326 Command Injection vulnerability in Netgate Pfsense and Pfsense Plus
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
network
low complexity
netgate CWE-77
8.8
2022-03-31 CVE-2022-24299 Improper Input Validation vulnerability in Netgate Pfsense and Pfsense Plus
Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.
network
low complexity
netgate CWE-20
8.8
2022-03-31 CVE-2022-26019 Path Traversal vulnerability in Netgate Pfsense and Pfsense Plus
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.
network
low complexity
netgate CWE-22
8.8