EIP-2026-110562
PRE-CVEpfSense 2.3.2 - Cross-Site Scripting / Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110562. PoCs published by Yann CAM.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in pfSense 2.3.2 that bypasses CSRF protections and leads to remote command execution as root via a reverse shell. The PoC includes JavaScript to extract CSRF tokens and execute system commands through the pfSense web interface.
Description
pfSense 2.3.2 - Cross-Site Scripting / Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in pfSense 2.3.2 that bypasses CSRF protections and leads to remote command execution as root via a reverse shell. The PoC includes JavaScript to extract CSRF tokens and execute system commands through the pfSense web interface.