CVE-2019-16667
HIGHpfSense 2.4.4-p3 - Cross-Site Request Forgery via diag_command.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-16667. PoCs published by ghost_fh.
AI-analyzed exploit summary This exploit leverages a CSRF vulnerability in pfSense (CVE-2019-16667) to execute arbitrary commands via a crafted HTML form. The PoC includes a reverse shell payload that triggers when a victim interacts with the malicious page.
Description
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
Exploits (1)
This exploit leverages a CSRF vulnerability in pfSense (CVE-2019-16667) to execute arbitrary commands via a crafted HTML form. The PoC includes a reverse shell payload that triggers when a victim interacts with the malicious page.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H