github.compatch
https://github.com/pfsense/FreeBSD-ports/commit/9e412edf62113303c36c7f7d5a48b0a3fb0be893 CVE-2025-34174
MEDIUM
Netgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site Scripting
Record summary
CVE-2025-34174 has a selected CVSS score of 5.1 (medium).
Description
In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 2.3.2_7 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-34174 redmine.pfsense.orgissue tracking
https://redmine.pfsense.org/issues/16413 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/netgate-pf-sense-ce-status-traffic-totals-stored-xss