← Back to list

Security Flaws in pfSense Firewall Uncovered: XSS and Command Injection Vulnerabilities Exposed”

Multiple security vulnerabilities have been identified in the open-source Netgate pfSense firewall solution, according to recent findings…

Ham · 2023-12-18 10:52 · 0 claps · 1.4 min read
#pfsense #security-vulnerabilities
Open on Medium ↗
Wiki topics: ☁️ · DevOps & Cloud 🔒 · Cybersecurity 🔓 · Open Source ⚖️ · Law & Justice 🥊 · Combat Sports

Security Flaws in pfSense Firewall Uncovered: XSS and Command Injection Vulnerabilities Exposed”

[embed]

Multiple security vulnerabilities have been identified in the open-source Netgate pfSense firewall solution, according to recent findings by Sonar. These vulnerabilities, if exploited, could allow attackers to execute arbitrary commands on affected appliances. The vulnerabilities affect pfSense CE 2.7.0 and below, as well as pfSense Plus 23.05.1 and below.

The issues are specifically related to two reflected cross-site scripting (XSS) bugs and one command injection flaw. Security researcher Oskar Zeino-Mahmalat highlighted the risks, noting that security within local networks is often more relaxed, trusting firewalls to protect against remote attacks. However, these vulnerabilities could potentially be used to spy on traffic or attack services within the local network.

The specific vulnerabilities are as follows:

  1. CVE-2023–42325 (CVSS score: 5.4): This is an XSS vulnerability that enables a remote attacker to gain privileges through a crafted URL directed at the status_logs_filter_dynamic.php page.
  2. CVE-2023–42327 (CVSS score: 5.4): Another XSS vulnerability allowing remote attackers to gain privileges via a crafted URL, this time targeting the getserviceproviders.php page.
  3. CVE-2023–42326 (CVSS score: 8.8): This is a command injection flaw due to a lack of validation, enabling remote attackers to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

Reflected XSS attacks, also known as non-persistent attacks, involve delivering a malicious script to a vulnerable web application, which is then returned in the HTTP response and executed in the victim’s web browser. Such attacks are typically initiated through crafted links in phishing messages, comments on websites, or social media posts. In the case of pfSense, the attacker could perform actions on the firewall with the victim’s permissions. Notably, since the pfSense process runs with root privileges for network configuration, this vulnerability could allow attackers to execute system commands as root.

Following responsible disclosure on July 3, 2023, these flaws were addressed in the subsequent releases of pfSense CE 2.7.1 and pfSense Plus 23.09.

This discovery comes weeks after Sonar detailed a remote code execution flaw in Microsoft Visual Studio Code’s npm integration (CVE-2023–36742, CVSS score: 7.8), which has been addressed in Microsoft’s Patch Tuesday updates for September 2023.


메타데이터
post_id
0cf3cad7ac3f
slug
security-flaws-in-pfsense-firewall-uncovered-xss-and-command-injection-vulnerabilities-exposed-0cf3cad7ac3f
url
https://medium.com/@vaadhoo/security-flaws-in-pfsense-firewall-uncovered-xss-and-command-injection-vulnerabilities-exposed-0cf3cad7ac3f
canonical_url
https://medium.com/@vaadhoo/security-flaws-in-pfsense-firewall-uncovered-xss-and-command-injection-vulnerabilities-exposed-0cf3cad7ac3f
author_url
https://medium.com/@vaadhoo
status
ok
fetched_at
2026-07-24 18:09:19