Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.
References
| Link | Resource |
|---|---|
| https://seclists.org/fulldisclosure/2026/Feb/16 | Exploit Mailing List Third Party Advisory |
| https://www.linkedin.com/in/nelson-adhepeau/ | Not Applicable |
| https://seclists.org/fulldisclosure/2026/Feb/16 | Exploit Mailing List Third Party Advisory |
Configurations
History
12 May 2026, 13:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:pfsense:pfsense:2.7.2:*:*:*:community:*:*:* | |
| First Time |
Pfsense pfsense
Pfsense |
|
| References | () https://seclists.org/fulldisclosure/2026/Feb/16 - Exploit, Mailing List, Third Party Advisory | |
| References | () https://www.linkedin.com/in/nelson-adhepeau/ - Not Applicable |
08 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://seclists.org/fulldisclosure/2026/Feb/16 - | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| CWE | CWE-502 CWE-915 |
08 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 07:16
Updated : 2026-05-12 13:45
NVD link : CVE-2025-69690
Mitre link : CVE-2025-69690
CVE.ORG link : CVE-2025-69690
JSON object : View
Products Affected
pfsense
- pfsense
