CVE-2024-46538

MEDIUM

pfSense 2.5.2 - Stored Cross-Site Scripting via $pconfig Variable in interfaces_groups_edit.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-46538. PoCs published by EQSTLab, LauLeysen.

AI-analyzed exploit summary This is a Python-based exploit for CVE-2024-46538, a stored XSS vulnerability in pfSense 2.5.2. It automates the process of injecting a malicious JavaScript payload via the interfaces_groups_edit.php page, which then executes arbitrary commands via a CSRF-protected endpoint.

Description

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.

Exploits (2)

nomisec WORKING POC 50 stars
by EQSTLab · poc
https://github.com/EQSTLab/CVE-2024-46538

This is a Python-based exploit for CVE-2024-46538, a stored XSS vulnerability in pfSense 2.5.2. It automates the process of injecting a malicious JavaScript payload via the interfaces_groups_edit.php page, which then executes arbitrary commands via a CSRF-protected endpoint.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: pfSense v2.5.2
Auth required
Prerequisites: Valid pfSense credentials · Access to the pfSense web interface · Network connectivity to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by LauLeysen · poc
https://github.com/LauLeysen/CVE-2024-46538

This is a Python-based exploit for CVE-2024-46538, a stored XSS vulnerability in pfSense v2.5.2. It leverages a crafted payload to execute arbitrary JavaScript, which then performs command execution and user creation via CSRF token manipulation.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: pfSense v2.5.2
Auth required
Prerequisites: Valid pfSense credentials · Network access to the pfSense web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 4.8
EPSS 0.7789
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
netgate/pfsense 2.5.2
Published Oct 22, 2024
Tracked Since Feb 18, 2026