CVE-2025-69691

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.
References
Link Resource
https://seclists.org/fulldisclosure/2026/Feb/16 Exploit Mailing List Third Party Advisory
https://www.linkedin.com/in/nelson-adhepeau/ Not Applicable
https://seclists.org/fulldisclosure/2026/Feb/16 Exploit Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:pfsense:pfsense:2.8.0:*:*:*:community:*:*:*

History

12 May 2026, 20:39

Type Values Removed Values Added
CPE cpe:2.3:a:pfsense:pfsense:2.8.0:*:*:*:community:*:*:*
First Time Pfsense pfsense
Pfsense
References () https://seclists.org/fulldisclosure/2026/Feb/16 - () https://seclists.org/fulldisclosure/2026/Feb/16 - Exploit, Mailing List, Third Party Advisory
References () https://www.linkedin.com/in/nelson-adhepeau/ - () https://www.linkedin.com/in/nelson-adhepeau/ - Not Applicable

08 May 2026, 22:16

Type Values Removed Values Added
CWE CWE-284
CWE-915
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.9
References () https://seclists.org/fulldisclosure/2026/Feb/16 - () https://seclists.org/fulldisclosure/2026/Feb/16 -

08 May 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 07:16

Updated : 2026-05-12 20:39


NVD link : CVE-2025-69691

Mitre link : CVE-2025-69691

CVE.ORG link : CVE-2025-69691


JSON object : View

Products Affected

pfsense

  • pfsense
CWE
CWE-284

Improper Access Control

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes