Release
pfSense CE 2.7.0
pfSense CE · 4 targets · 4 artifacts
Release Facts
- Version
- 2.7.0
- Date
- Architectures
- amd64
- Editions
- ce
- Variants
- iso, memstick, memstick-adi, memstick-serial
- Protocols
- https
Quality
- Targets
- 4
- Artifacts
- 4
- Checksums
- 4/4
- Average confidence
- 1.00
- CVEs
- 7
Artifacts
| Artifact | Media | Size | Protocols | Checksums | Quality |
|---|---|---|---|---|---|
| pfSense-CE-2.7.0-RELEASE-amd64.iso.gz | iso | 473 MB | https | 1 | 1.00 |
| pfSense-CE-memstick-2.7.0-RELEASE-amd64.img.gz | disk-image | 476 MB | https | 1 | 1.00 |
| pfSense-CE-memstick-ADI-2.7.0-RELEASE-amd64.img.gz | disk-image | 474 MB | https | 1 | 1.00 |
| pfSense-CE-memstick-serial-2.7.0-RELEASE-amd64.img.gz | disk-image | 474 MB | https | 1 | 1.00 |
Related CVEs
- CVE-2022-29273
MEDIUM · pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
- CVE-2023-27253
HIGH · A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
- CVE-2023-42325
MEDIUM · Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.
- CVE-2023-42326
HIGH · An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
- CVE-2023-42327
MEDIUM · Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
- CVE-2023-48123
HIGH · An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.
- CVE-2026-67189
MEDIUM · pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.