Netgate Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Netgate products.
Products
- pfSense CE7 vulnerabilities
- Netgate pfSense3 vulnerabilities
- pfSense2 vulnerabilities
- Amiti Antivirus1 vulnerability
- Data Backup1 vulnerability
- NETGATE AMITI Antivirus1 vulnerability
- NETGATE Registry Cleaner1 vulnerability
- pfblockerng1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2016-20058HIGH | Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege EscalationNetgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges. CWE-428Apr 4, 2026 | CVSS8.5v4.0 | EPSS0.718% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-20057HIGH | NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege EscalationNETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges. CWE-428Apr 4, 2026 | CVSS8.5v4.0 | EPSS0.606% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25271HIGH | NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service PathNETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations. CWE-428Feb 4, 2026 | CVSS8.5v4.0 | EPSS0.329% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25269HIGH | Amiti Antivirus 25.0.640 - Unquoted Service Path VulnerabilityAmiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges by placing executable files in specific directory locations. CWE-428Feb 4, 2026 | CVSS8.5v4.0 | EPSS0.329% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12490HIGH | Netgate pfSense CE Suricata Path Traversal Remote Code Execution VulnerabilityNetgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists within the Suricata package. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of… CWE-22Nov 6, 2025 | CVSS8.8v3.0 | EPSS20.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34178MEDIUM | Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site ScriptingIn pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions. CWE-79Sep 9, 2025 | CVSS5.1v4.0 | EPSS3.64% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34177MEDIUM | Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site ScriptingIn pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions. CWE-79Sep 9, 2025 | CVSS5.1v4.0 | EPSS0.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34176MEDIUM | Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information DisclosureIn pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions. CWE-22Sep 9, 2025 | CVSS5.3v4.0 | EPSS14.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34175MEDIUM | Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site ScriptingIn pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated. CWE-79Sep 9, 2025 | CVSS5.1v4.0 | EPSS15.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34174MEDIUM | Netgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site ScriptingIn pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions. CWE-79Sep 9, 2025 | CVSS5.1v4.0 | EPSS10.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34173MEDIUM | Netgate pfSense CE Snort package v4.1.6_25 Directory Traversal Information DisclosureIn pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: Snort package" permissions. CWE-22Sep 9, 2025 | CVSS5.3v4.0 | EPSS0.896% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34172MEDIUM | Netgate pfSense CE HAProxy Package 0.63_10 Reflected Cross-Site ScriptingIn pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated. CWE-79Sep 9, 2025 | CVSS4.8v4.0 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53392MEDIUM | In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI. CWE-36Jun 28, 2025 | CVSS5.0v3.1 | EPSS1.81% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-31814CRITICAL | netgate pfblockerng Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected. | CVSS9.8v3.1 | EPSS87.8% | PoCs10 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-4019HIGH | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_normal_mode` parameter. CWE-78Dec 3, 2018 | CVSS7.2v3.1 | EPSS48.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-4020HIGH | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_ac_mode` POST parameter parameter. CWE-78Dec 3, 2018 | CVSS7.2v3.1 | EPSS48.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-4021HIGH | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_battery_mode` POST parameter. CWE-78Dec 3, 2018 | CVSS7.2v3.1 | EPSS72.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |