Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.
An attacker with administrator privileges can use the module installer in pfSense CE 2.7.2 by uploading a crafted backup file. This file contains a serialized PHP object utilizing the post_reboot_commands property. When the file is processed by the application, the object is deserialized (CWE-502), leading to the execution of embedded commands. The vulnerability is also related to insufficient control of properties modified by the user during deserialization (CWE-915).
An authenticated administrator can achieve full code execution (RCE) on the pfSense server, potentially taking control of the network device and the entire infrastructure managed by the firewall.
Patches available from the vendor should be applied according to the references. Additionally, access to the pfSense administrative interface should be restricted to trusted hosts and management networks only, applying the principle of least privilege. It is worth noting that the vendor disputes the classification of this behavior as a vulnerability.
Netgate pfSense CE version 2.7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HPfsense
APPPfsense2.7.2
Related vulnerabilities
Netgate pfSense CE 2.8.0 — RCE przez XMLRPC API (pfsense.exec_php)
pfSense CE 2.6.0 — przejęcie kont przez słabą politykę haseł
Obejście ochrony przed brute force w SSHGuard — pfSense Plus i pfSense CE
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without ve...
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a r...