CVE-2025-69690

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.
References
Link Resource
https://seclists.org/fulldisclosure/2026/Feb/16 Exploit Mailing List Third Party Advisory
https://www.linkedin.com/in/nelson-adhepeau/ Not Applicable
https://seclists.org/fulldisclosure/2026/Feb/16 Exploit Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:pfsense:pfsense:2.7.2:*:*:*:community:*:*:*

History

No history.

Information

Published : 2026-05-08 07:16

Updated : 2026-06-17 10:00


NVD link : CVE-2025-69690

Mitre link : CVE-2025-69690

CVE.ORG link : CVE-2025-69690


JSON object : View

Products Affected

pfsense

  • pfsense
CWE
CWE-502

Deserialization of Untrusted Data

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes