CVE-2025-69690

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.
References
Link Resource
https://seclists.org/fulldisclosure/2026/Feb/16 Exploit Mailing List Third Party Advisory
https://www.linkedin.com/in/nelson-adhepeau/ Not Applicable
https://seclists.org/fulldisclosure/2026/Feb/16 Exploit Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:pfsense:pfsense:2.7.2:*:*:*:community:*:*:*

History

12 May 2026, 13:45

Type Values Removed Values Added
CPE cpe:2.3:a:pfsense:pfsense:2.7.2:*:*:*:community:*:*:*
First Time Pfsense pfsense
Pfsense
References () https://seclists.org/fulldisclosure/2026/Feb/16 - () https://seclists.org/fulldisclosure/2026/Feb/16 - Exploit, Mailing List, Third Party Advisory
References () https://www.linkedin.com/in/nelson-adhepeau/ - () https://www.linkedin.com/in/nelson-adhepeau/ - Not Applicable

08 May 2026, 22:16

Type Values Removed Values Added
References () https://seclists.org/fulldisclosure/2026/Feb/16 - () https://seclists.org/fulldisclosure/2026/Feb/16 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-502
CWE-915

08 May 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 07:16

Updated : 2026-05-12 13:45


NVD link : CVE-2025-69690

Mitre link : CVE-2025-69690

CVE.ORG link : CVE-2025-69690


JSON object : View

Products Affected

pfsense

  • pfsense
CWE
CWE-502

Deserialization of Untrusted Data

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes