Command Injection Vulnerability in Netgate pfSense CE by Netgate
CVE-2018-4020
What is CVE-2018-4020?
A command injection vulnerability exists in Netgate pfSense CE 2.4.4-RELEASE due to improper processing of parameters in specific POST requests. This flaw allows an authenticated attacker to execute arbitrary commands on the system by manipulating the powerd_ac_mode POST parameter while sending valid requests to the administration web interface. The implications of this vulnerability can lead to unauthorized access and control of the affected system, highlighting the importance of securing administration interfaces.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Netgate pfSense Netgate pfSense CE 2.4.4-RELEASE
References
EPSS Score
84% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
