CVE-2025-69691

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
08/05/2026
Last modified:
12/05/2026

Description

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pfsense:pfsense:2.8.0:*:*:*:community:*:*:*