Netgate Vulnerabilities and Affected Products
Vulnerabilities associated with pfSense.
Products
Clear product- pfSense CE7 vulnerabilities
- Netgate pfSense3 vulnerabilities
- pfSense2 vulnerabilities
- Amiti Antivirus1 vulnerability
- Data Backup1 vulnerability
- NETGATE AMITI Antivirus1 vulnerability
- NETGATE Registry Cleaner1 vulnerability
- pfblockerng1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-12490HIGH | Netgate pfSense CE Suricata Path Traversal Remote Code Execution VulnerabilityNetgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists within the Suricata package. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of… CWE-22Nov 6, 2025 | CVSS8.8v3.0 | EPSS20.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53392MEDIUM | In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI. CWE-36Jun 28, 2025 | CVSS5.0v3.1 | EPSS1.81% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |