CVE-2025-34176

MEDIUM

pfSense < 2.8.0 - Authenticated Path Traversal in Suricata IP Reputation Check

Title source: llm
STIX 2.1

Description

In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

Scores

CVSS v3 4.3
EPSS 0.1401
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
pfsense/pfsense < 2.8.0
Published Sep 09, 2025
Tracked Since Feb 18, 2026