Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.
References
| Link | Resource |
|---|---|
| https://seclists.org/fulldisclosure/2026/Feb/16 | Exploit Mailing List Third Party Advisory |
| https://www.linkedin.com/in/nelson-adhepeau/ | Not Applicable |
| https://seclists.org/fulldisclosure/2026/Feb/16 | Exploit Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-05-08 07:16
Updated : 2026-06-17 10:00
NVD link : CVE-2025-69691
Mitre link : CVE-2025-69691
CVE.ORG link : CVE-2025-69691
JSON object : View
Products Affected
pfsense
- pfsense
