Code Execution Vulnerability in Netgate pfSense CE by Netgate
CVE-2025-69690

9.1CRITICAL

Key Information:

Vendor

Netgate

Vendor
CVE Published:
8 May 2026

What is CVE-2025-69690?

The vulnerability in Netgate pfSense CE 2.7.2 allows unauthorized code execution through the module installer. This occurs when an attacker utilizes a backup file containing a serialized PHP object that defines the 'post_reboot_commands' property. Despite the supplier's claim that this installer is only accessible to administrators, the existence of this flaw poses a significant risk, as it enables the execution of arbitrary PHP code. Proper safeguards and caution are recommended to mitigate the potential exploitation of this vulnerability.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.