CVE-2025-53392

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.
Configurations

No configuration.

History

30 Jun 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) En Netgate pfSense CE 2.8.0, el privilegio "WebCfg - Diagnóstico: Comando" permite leer archivos arbitrarios mediante la navegación del directorio diag_command.php dlPath. NOTA: El proveedor considera que este es el comportamiento previsto para este nivel de privilegio y que los administradores del sistema están informados a través de la documentación del producto y la interfaz de usuario.
References () https://github.com/skraft9/pfsense-security-research - () https://github.com/skraft9/pfsense-security-research -

28 Jun 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-28 23:15

Updated : 2025-06-30 18:38


NVD link : CVE-2025-53392

Mitre link : CVE-2025-53392

CVE.ORG link : CVE-2025-53392


JSON object : View

Products Affected

No product.

CWE
CWE-36

Absolute Path Traversal