PT-2026-20263 · Pfsense · Pfsense
Published
2026-02-17
·
Updated
2026-05-12
·
CVE-2025-69691
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netgate pfSense CE version 2.8.0
Description
Code execution is possible in the XMLRPC API through the
pfsense.exec php function. This functionality is available to administrators, who are intentionally permitted to execute PHP code.Recommendations
Restrict access to the XMLRPC API to minimize the risk of unauthorized code execution.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pfsense