This exploit demonstrates a directory traversal vulnerability in PFSense <= 2.2.5 via unsanitized XML file inclusion in wizard.php and pkg.php, leading to arbitrary file inclusion and potential RCE.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:PFSense <= 2.2.5
No auth needed
Prerequisites:Access to the target's web interface · Ability to upload or reference a malicious XML file