← Back to browse · API

CVE-2025-69691

Severity
CRITICAL
CVSS
9.9
EPSS
0.0053
Risk score
39.79
CISA KEV
No
PoC
No
Published
2026-05-08
Modified
2026-05-08
First seen
2026-08-07
Aliases
EUVD-2025-209739, GHSA-7WW6-9Q8H-2G49
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-209739

Description

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

References