Code Execution Vulnerability in Netgate pfSense CE by Netgate
CVE-2025-69690
9.1CRITICAL
What is CVE-2025-69690?
The vulnerability in Netgate pfSense CE 2.7.2 allows unauthorized code execution through the module installer. This occurs when an attacker utilizes a backup file containing a serialized PHP object that defines the 'post_reboot_commands' property. Despite the supplier's claim that this installer is only accessible to administrators, the existence of this flaw poses a significant risk, as it enables the execution of arbitrary PHP code. Proper safeguards and caution are recommended to mitigate the potential exploitation of this vulnerability.
