ISOMAN

Filtered CVEs

pfSense-CE-memstick-ADI-2.6.0-RELEASE-amd64.img.gz CVEs

CVEs linked through pfSense CE 2.6.0 amd64 ce memstick-adi.

Release Context

  1. pfSense CE · 2.6.0 amd64 ce memstick-adi

15 CVEs

  1. CVE-2026-67189
    MEDIUM · CVSS 5.3 ·

    pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.

  2. CVE-2025-34178
    MEDIUM · CVSS 5.1 ·

    In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

  3. CVE-2025-34177
    MEDIUM · CVSS 5.1 ·

    In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

  4. CVE-2025-34176
    MEDIUM · CVSS 5.3 ·

    In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

  5. CVE-2025-34175
    MEDIUM · CVSS 5.1 ·

    In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated.

  6. CVE-2025-34174
    MEDIUM · CVSS 5.1 ·

    In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions.

  7. CVE-2025-34173
    MEDIUM · CVSS 5.3 ·

    In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: Snort package" permissions.

  8. CVE-2025-34172
    MEDIUM · CVSS 4.8 ·

    In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.

  9. CVE-2023-48123
    HIGH · CVSS 8.8 ·

    An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

  10. CVE-2023-42326
    HIGH · CVSS 8.8 ·

    An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

  11. CVE-2023-29975
    HIGH · CVSS 7.2 ·

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

  12. CVE-2023-29974
    CRITICAL · CVSS 9.8 ·

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

  13. CVE-2023-29973
    MEDIUM · CVSS 4.9 ·

    Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users in firewall.

  14. CVE-2023-27100
    CRITICAL · CVSS 9.8 ·

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

  15. CVE-2022-29273
    MEDIUM · CVSS 6.1 ·

    pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.