Blog | G5 Cyber Security

Vulnerability Spotlight: Netgate pfSense system_advanced_misc.php Multiple Command Injection Vulnerabilities

Cisco Talos is disclosing a command injection vulnerability in Netgate pfSense system_advanced_misc.php powerd_normal_mode. The vulnerability is due to the lack of sanitization on the ‘powerd_ac_mode’parameter in POST requests to’system.advanced.php. When processing requests to /system_adv.php, Netgate.pfSense firewall does not properly sanitize the powerd.normalparameter”]

Source: https://blog.talosintelligence.com/2018/12/Netgate-pfsense-command-injection-vulns.html

Exit mobile version