Security Flaws in pfSense Firewall Uncovered: XSS and Command Injection Vulnerabilities Exposed”
Multiple security vulnerabilities have been identified in the open-source Netgate pfSense firewall solution, according to recent findings…
Security Flaws in pfSense Firewall Uncovered: XSS and Command Injection Vulnerabilities Exposed”
[embed]
Multiple security vulnerabilities have been identified in the open-source Netgate pfSense firewall solution, according to recent findings by Sonar. These vulnerabilities, if exploited, could allow attackers to execute arbitrary commands on affected appliances. The vulnerabilities affect pfSense CE 2.7.0 and below, as well as pfSense Plus 23.05.1 and below.
The issues are specifically related to two reflected cross-site scripting (XSS) bugs and one command injection flaw. Security researcher Oskar Zeino-Mahmalat highlighted the risks, noting that security within local networks is often more relaxed, trusting firewalls to protect against remote attacks. However, these vulnerabilities could potentially be used to spy on traffic or attack services within the local network.
The specific vulnerabilities are as follows:
- CVE-2023–42325 (CVSS score: 5.4): This is an XSS vulnerability that enables a remote attacker to gain privileges through a crafted URL directed at the
status_logs_filter_dynamic.phppage. - CVE-2023–42327 (CVSS score: 5.4): Another XSS vulnerability allowing remote attackers to gain privileges via a crafted URL, this time targeting the
getserviceproviders.phppage. - CVE-2023–42326 (CVSS score: 8.8): This is a command injection flaw due to a lack of validation, enabling remote attackers to execute arbitrary code via a crafted request to the
interfaces_gif_edit.phpandinterfaces_gre_edit.phpcomponents.
Reflected XSS attacks, also known as non-persistent attacks, involve delivering a malicious script to a vulnerable web application, which is then returned in the HTTP response and executed in the victim’s web browser. Such attacks are typically initiated through crafted links in phishing messages, comments on websites, or social media posts. In the case of pfSense, the attacker could perform actions on the firewall with the victim’s permissions. Notably, since the pfSense process runs with root privileges for network configuration, this vulnerability could allow attackers to execute system commands as root.
Following responsible disclosure on July 3, 2023, these flaws were addressed in the subsequent releases of pfSense CE 2.7.1 and pfSense Plus 23.09.
This discovery comes weeks after Sonar detailed a remote code execution flaw in Microsoft Visual Studio Code’s npm integration (CVE-2023–36742, CVSS score: 7.8), which has been addressed in Microsoft’s Patch Tuesday updates for September 2023.
메타데이터
- post_id
- 0cf3cad7ac3f
- slug
- security-flaws-in-pfsense-firewall-uncovered-xss-and-command-injection-vulnerabilities-exposed-0cf3cad7ac3f
- url
- https://medium.com/@vaadhoo/security-flaws-in-pfsense-firewall-uncovered-xss-and-command-injection-vulnerabilities-exposed-0cf3cad7ac3f
- canonical_url
- https://medium.com/@vaadhoo/security-flaws-in-pfsense-firewall-uncovered-xss-and-command-injection-vulnerabilities-exposed-0cf3cad7ac3f
- author_url
- https://medium.com/@vaadhoo
- status
- ok
- fetched_at
- 2026-07-24 18:09:19