Netgate Vulnerabilities and Affected Products
Vulnerabilities associated with pfSense CE.
Products
Clear product- pfSense CE7 vulnerabilities
- Netgate pfSense3 vulnerabilities
- pfSense2 vulnerabilities
- Amiti Antivirus1 vulnerability
- Data Backup1 vulnerability
- NETGATE AMITI Antivirus1 vulnerability
- NETGATE Registry Cleaner1 vulnerability
- pfblockerng1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-34178MEDIUM | Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site ScriptingIn pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions. CWE-79Sep 9, 2025 | CVSS5.1v4.0 | EPSS3.64% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34177MEDIUM | Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site ScriptingIn pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions. CWE-79Sep 9, 2025 | CVSS5.1v4.0 | EPSS0.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34176MEDIUM | Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information DisclosureIn pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions. CWE-22Sep 9, 2025 | CVSS5.3v4.0 | EPSS14.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34175MEDIUM | Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site ScriptingIn pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated. CWE-79Sep 9, 2025 | CVSS5.1v4.0 | EPSS15.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34174MEDIUM | Netgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site ScriptingIn pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions. CWE-79Sep 9, 2025 | CVSS5.1v4.0 | EPSS10.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34173MEDIUM | Netgate pfSense CE Snort package v4.1.6_25 Directory Traversal Information DisclosureIn pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: Snort package" permissions. CWE-22Sep 9, 2025 | CVSS5.3v4.0 | EPSS0.896% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-34172MEDIUM | Netgate pfSense CE HAProxy Package 0.63_10 Reflected Cross-Site ScriptingIn pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated. CWE-79Sep 9, 2025 | CVSS4.8v4.0 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |