CVE-2010-20059

CRITICAL

FreeNAS <0.7.2-5543 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2010-20059. PoCs published by Metasploit, MC, including Metasploit module exploits/multi/http/freenas_exec_raw.

AI-analyzed exploit summary This Metasploit module exploits an arbitrary command execution vulnerability in FreeNAS 0.7.2 < rev.5543 via the exec_raw.php page. It sends a crafted URI to write a PHP payload to the server and then triggers it to achieve remote code execution.

Description

FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16313

This Metasploit module exploits an arbitrary command execution vulnerability in FreeNAS 0.7.2 < rev.5543 via the exec_raw.php page. It sends a crafted URI to write a PHP payload to the server and then triggers it to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: FreeNAS 0.7.2 < rev.5543
No auth needed
Prerequisites: Network access to the target · FreeNAS web interface exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by MC · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/freenas_exec_raw.rb

This Metasploit module exploits a command injection vulnerability in FreeNAS 0.7.2 < rev.5543 via the exec_raw.php endpoint. It sends a crafted URI to write a PHP payload to the server and then triggers it to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: FreeNAS 0.7.2 < rev.5543
No auth needed
Prerequisites: Network access to the target · FreeNAS web interface exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 9.3
EPSS 0.0095
EPSS Percentile 56.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
iXsystems/FreeNAS < 0.7.2 rev 5543
Published Aug 20, 2025
Tracked Since Feb 18, 2026