Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 08 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XMLRPC API Code Execution in Netgate pfSense CE 2.8.0 | |
| First Time appeared |
Pfsense
Pfsense pfsense |
|
| Weaknesses | CWE-94 | |
| Vendors & Products |
Pfsense
Pfsense pfsense |
Fri, 08 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-08T05:51:51.358Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69691
No data.
Status : Received
Published: 2026-05-08T07:16:28.880
Modified: 2026-05-08T07:16:28.880
Link: CVE-2025-69691
No data.
OpenCVE Enrichment
Updated: 2026-05-08T07:30:03Z
Weaknesses