CVE-2010-20059
FreeNAS <0.7.2-5543 - Command Injection
Title source: llmDescription
FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16313
metasploit
WORKING POC
GREAT
by MC · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/freenas_exec_raw.rb
References (8)
Scores
EPSS
0.4441
EPSS Percentile
97.5%
Classification
CWE
CWE-78
Status
draft
Timeline
Published
Aug 20, 2025
Tracked Since
Feb 18, 2026