CRITICAL🇵🇱 Wersja polska

CVE-2025-69690

CVSS 9.1v3.1pub. 2026-05-08upd. 2026-05-12

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.

🤖 AI Analysis
How it works

An attacker with administrator privileges can use the module installer in pfSense CE 2.7.2 by uploading a crafted backup file. This file contains a serialized PHP object utilizing the post_reboot_commands property. When the file is processed by the application, the object is deserialized (CWE-502), leading to the execution of embedded commands. The vulnerability is also related to insufficient control of properties modified by the user during deserialization (CWE-915).

Impact

An authenticated administrator can achieve full code execution (RCE) on the pfSense server, potentially taking control of the network device and the entire infrastructure managed by the firewall.

Mitigation & patch

Patches available from the vendor should be applied according to the references. Additionally, access to the pfSense administrative interface should be restricted to trusted hosts and management networks only, applying the principle of least privilege. It is worth noting that the vendor disputes the classification of this behavior as a vulnerability.

Who is affected

Netgate pfSense CE version 2.7.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Pfsense

    APP
    Pfsense
    2.7.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2025-69691CRITICAL9.9PL ✓same product

Netgate pfSense CE 2.8.0 — RCE przez XMLRPC API (pfsense.exec_php)

CVE-2023-29974CRITICAL9.8PL ✓same product

pfSense CE 2.6.0 — przejęcie kont przez słabą politykę haseł

CVE-2023-27100CRITICAL9.8PL ✓same product

Obejście ochrony przed brute force w SSHGuard — pfSense Plus i pfSense CE

CVE-2023-29975HIGH7.2same product

An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without ve...

CVE-2020-19678HIGH7.5same product

Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a r...