Artifact
pfSense-CE-memstick-2.7.0-RELEASE-amd64.img.gz
pfSense CE · 2.7.0 amd64 ce memstick · disk-image · 476 MB
Checksums
Quality
- Confidence
- 1.00
- Missing checksum
- no
- Missing architecture
- no
- Stale downloads
- 0
- Audited
Download Sources
| Protocol | Type | Status | URL |
|---|---|---|---|
| https | official-mirror · direct_artifact | ok 200 | https://atxfiles.netgate.com/mirror/downloads/pfSense-CE-memstick-2.7.0-RELEASE-amd64.img.gz |
Related CVEs
- CVE-2022-29273
MEDIUM · pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
- CVE-2023-27253
HIGH · A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
- CVE-2023-42325
MEDIUM · Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.
- CVE-2023-42326
HIGH · An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
- CVE-2023-42327
MEDIUM · Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
- CVE-2023-48123
HIGH · An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.
- CVE-2026-67189
MEDIUM · pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.