CVE-2025-34312
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
28/10/2025
Last modified:
03/11/2025
Description
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist. When a blacklist is installed the application issues an HTTP POST to /cgi-bin/urlfilter.cgi and interpolates the value of BE_NAME directly into a shell invocation without appropriate sanitation. Crafted input can inject shell metacharacters, leading to arbitrary command execution in the context of the 'nobody' user.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ipfire:ipfire:*:*:*:*:*:*:*:* | 2.29 (excluding) | |
| cpe:2.3:a:ipfire:ipfire:2.29:core_update183:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update184:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update185:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update186:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update187:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update188:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update189:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update190:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update191:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update192:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update193:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update194:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update195:*:*:*:*:*:* | ||
| cpe:2.3:a:ipfire:ipfire:2.29:core_update196:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



