Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.
References
| Link | Resource |
|---|---|
| https://seclists.org/fulldisclosure/2026/Feb/16 | Exploit Mailing List Third Party Advisory |
| https://www.linkedin.com/in/nelson-adhepeau/ | Not Applicable |
| https://seclists.org/fulldisclosure/2026/Feb/16 | Exploit Mailing List Third Party Advisory |
Configurations
History
12 May 2026, 20:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:pfsense:pfsense:2.8.0:*:*:*:community:*:*:* | |
| First Time |
Pfsense pfsense
Pfsense |
|
| References | () https://seclists.org/fulldisclosure/2026/Feb/16 - Exploit, Mailing List, Third Party Advisory | |
| References | () https://www.linkedin.com/in/nelson-adhepeau/ - Not Applicable |
08 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 CWE-915 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
| References | () https://seclists.org/fulldisclosure/2026/Feb/16 - |
08 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 07:16
Updated : 2026-05-12 20:39
NVD link : CVE-2025-69691
Mitre link : CVE-2025-69691
CVE.ORG link : CVE-2025-69691
JSON object : View
Products Affected
pfsense
- pfsense
