PT-2025-21162 · Openvpn+1 · Openvpn+1

Published

2024-11-15

·

Updated

2025-05-19

·

CVE-2024-54780

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: pfSense CE versions prior to 2.8.0 beta release corresponding Plus builds versions prior to 2.8.0 beta release
Description: The issue is related to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this by injecting arbitrary OpenVPN management commands via the remipp parameter.
Recommendations: For pfSense CE versions prior to 2.8.0 beta release, update to version 2.8.0 beta or later to resolve the issue. For corresponding Plus builds versions prior to 2.8.0 beta release, update to version 2.8.0 beta or later to resolve the issue. As a temporary workaround, consider restricting access to the OpenVPN management interface to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00176
CVE-2024-54780

Affected Products

Openvpn
Pfsense Ce