Record summary

CVE-2025-34174 has a selected CVSS score of 5.1 (medium).

Description

In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

pfSense CE

Browse Netgate / pfSense CEStatus_Traffic_Totals

Default status: unaffected

CVE List2.3.2_7affected

References

4