CVE-2024-54780

HIGH

pfSense CE < 2.8.0 and Plus < 25.03 - Authenticated Command Injection via OpenVPN Widget remipp Parameter

Title source: llm
STIX 2.1

Description

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.

Scores

CVSS v3 8.8
EPSS 0.1159
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
netgate/pfsense_ce < 2.8.0
netgate/pfsense_plus < 25.03
Published May 14, 2025
Tracked Since Feb 18, 2026