Record summary

CVE-2022-40624 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 17, 2025 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubdhammon/pfBlockerNg-CVE-2022-40624Repository PoCby dhammonStars: 2Not analyzed2 files

2.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALpfSense pfBlockerNG - OS Command InjectionCVSS 9.8

pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header.

Impact

Allows remote attackers to execute arbitrary code on the affected system

Remediation

Update to the latest version of pfSense pfBlockerNG to mitigate CVE-2022-40624

WeaknessesCWE-78
Authorsritikchaddha
Template tagscvecve2022pfsensepfblockerngrcesqlinetgatevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:pfsense:pfblockerng:*:*:*:*:*:*:*:*
Shodan: pfBlockerNG
FOFA: pfBlockerNG

Source: ProjectDiscovery

References

4