EIP-2026-110566
PRE-CVEpfSense Firewall 2.2.6 - Services Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110566. PoCs published by Aatif Shahdad.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in pfSense Firewall <= 2.2.6, allowing an attacker to coerce a logged-in victim's browser to issue requests that start/stop/restart services on the firewall. The PoC includes HTML forms that submit crafted requests to the vulnerable endpoint.
Description
pfSense Firewall 2.2.6 - Services Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a CSRF vulnerability in pfSense Firewall <= 2.2.6, allowing an attacker to coerce a logged-in victim's browser to issue requests that start/stop/restart services on the firewall. The PoC includes HTML forms that submit crafted requests to the vulnerable endpoint.