EIP-2026-104749
PRE-CVEpfSense 2.4.1 - Cross-Site Request Forgery Error Page Clickjacking (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104749. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a clickjacking vulnerability in pfSense <= 2.4.1 by tricking an authenticated admin into executing arbitrary PHP commands via a crafted webpage. It leverages a hidden iframe and JavaScript to submit a malicious form to the pfSense WebGUI's diag_command.php endpoint.
Description
pfSense 2.4.1 - Cross-Site Request Forgery Error Page Clickjacking (Metasploit)
Exploits (1)
This Metasploit module exploits a clickjacking vulnerability in pfSense <= 2.4.1 by tricking an authenticated admin into executing arbitrary PHP commands via a crafted webpage. It leverages a hidden iframe and JavaScript to submit a malicious form to the pfSense WebGUI's diag_command.php endpoint.