In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.
References
Configurations
No configuration.
History
30 Jun 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://github.com/skraft9/pfsense-security-research - |
28 Jun 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-28 23:15
Updated : 2025-06-30 18:38
NVD link : CVE-2025-53392
Mitre link : CVE-2025-53392
CVE.ORG link : CVE-2025-53392
JSON object : View
Products Affected
No product.
CWE
CWE-36
Absolute Path Traversal