{"id":4074,"date":"2025-05-20T10:03:47","date_gmt":"2025-05-20T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/20\/multiple-pfsense-firewall-vulnerabilities-let-attackers-inject-malicious-codes\/"},"modified":"2025-05-20T10:03:47","modified_gmt":"2025-05-20T10:03:47","slug":"multiple-pfsense-firewall-vulnerabilities-let-attackers-inject-malicious-codes","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/20\/multiple-pfsense-firewall-vulnerabilities-let-attackers-inject-malicious-codes\/","title":{"rendered":"Multiple pfSense Firewall Vulnerabilities Let Attackers Inject Malicious Codes"},"content":{"rendered":"<p>    Multiple pfSense Firewall Vulnerabilities Let Attackers Inject Malicious Codes<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Three critical vulnerabilities in pfSense firewall software that could allow authenticated attackers to inject malicious code, manipulate <a href=\"https:\/\/cybersecuritynews.com\/cloud-service-providers\/\" target=\"_blank\" rel=\"noreferrer noopener\">cloud backups<\/a>, and potentially achieve remote code execution.\u00a0<\/p>\n<p>The vulnerabilities affect both pfSense Community Edition (CE) prior to version 2.8.0 beta and corresponding pfSense Plus builds.<\/p>\n<p>These flaws, CVE-2024-57273, CVE-2024-54780, and CVE-2024-54779, exploit weaknesses in the Automatic Configuration Backup (ACB) service, OpenVPN widget, and dashboard widgets.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Exploiting Cloud Backups via SSH Key Derivation (CVE-2024-57273)<\/strong><\/h2>\n<p>The first vulnerability, CVE-2024-57273, affects the Automatic Configuration Backup (ACB) service and enables attackers to hijack cloud backup keys.\u00a0<\/p>\n<p>This flaw could lead to deletion of backups, stored <a href=\"https:\/\/cybersecuritynews.com\/okta-browser-plugin-xss-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">cross-site scripting (XSS)<\/a> attacks, and information leakage.<\/p>\n<p>The exploitation of CVE-2024-57273 requires two conditions: an accessible SSH server and ACB configured on the firewall.\u00a0<\/p>\n<p>The vulnerability stems from how the API key for cloud backups is derived from the public SSH key in \/etc\/ssh\/ssh_host_ed25519_key.pub. As noted in the researcher\u2019s blog, \u201cit is easy for someone to derive the key and delete your cloud backups or poison them\u201d.<\/p>\n<p>A particularly concerning example shows how attackers can inject JavaScript code into the \u201creason\u201d field of backups:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXejOYCmYKZ9y3LVFJw3xz35zvgwv3ulQW_DCgLDnbLdHEeDMa9FyCYXw6J4iZYZ0sNnAj6mO9vn_00CFvf211lARb-24ANNDIpBq7XlLqXphBi33TcI8V2PXJJ5KYFeyzGBHotGpA?key=-bjGmosbNY3lJqlOaJ4c6Q\" alt=\"\"><\/figure>\n<\/div>\n<p>When an administrator views the backup list, this malicious code executes in their browser.<\/p>\n<h2 class=\"wp-block-heading\"><strong>OpenVPN Command Injection (CVE-2024-54780)<\/strong><\/h2>\n<p>The second vulnerability, CVE-2024-54780, involves command injection in the OpenVPN widget.\u00a0<\/p>\n<p>This authenticated vulnerability allows attackers to inject arbitrary OpenVPN management commands via the unsanitized remipp parameter.\u00a0<\/p>\n<p>The vulnerability exists because user inputs are passed directly to the OpenVPN management interface without proper sanitization:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeKV-z_JnrxIG_7X_-Vm4OP9sPxOcv0Sku6fdLh5cNGBqZh5GWl-ICTrTz40ablLeZaAJoLXWLg9bAoXSTSwnqH6gI9H9AwV4-ckooo7JQ6Cz9TtYFtpU2CahqJbmUW-ioua4GwXA?key=-bjGmosbNY3lJqlOaJ4c6Q\" alt=\"\"><\/figure>\n<\/div>\n<p>An attacker can inject a newline character followed by another command, such as remipp=5%0Astatus, resulting in two commands being executed.<\/p>\n<h2 class=\"wp-block-heading\"><strong>XML Injection via Dashboard Widgets (CVE-2024-54779)<\/strong><\/h2>\n<p>The third vulnerability, CVE-2024-54779, allows <a href=\"https:\/\/cybersecuritynews.com\/poc-exploit-xxe-injection-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">XML injection<\/a> in dashboard widgets through the widgetkey parameter. This can lead to configuration file corruption and persistent XSS attacks.\u00a0<\/p>\n<p>The vulnerable code directly incorporates the widgetkey value into XML structures without sanitization:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXezods5CeZftwILUpIV2CJlcFlMae-Lp97uFcX3TcIVhG2Rsr5OJmEqQ9vc8Q2zQsJUrSBFDgsF4mswLZ13A7SJa-smDEz_8Qmw9HlhtnJvY_a3QSWCHSywn6IHKlbBp1Mo3ZwYsQ?key=-bjGmosbNY3lJqlOaJ4c6Q\" alt=\"\"><\/figure>\n<\/div>\n<p>In a worst-case scenario, this can prevent the firewall from bootstrapping properly, causing a denial of service.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVEs<\/strong><\/td>\n<td><strong>Affected Products<\/strong><\/td>\n<td><strong>Impact<\/strong><\/td>\n<td><strong>Exploit Prerequisites<\/strong><\/td>\n<td><strong>CVSS 3.1 Score<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2024-57273<\/td>\n<td>pfSense CE (prior to 2.8.0 beta) and pfSense Plus builds<\/td>\n<td>Stored XSS in ACB service, backup deletion, and information leakage\u00a0<\/td>\n<td>Accessible SSH server + ACB configuration enabled\u00a0<\/td>\n<td>5.4 (Medium)<\/td>\n<\/tr>\n<tr>\n<td>CVE-2024-54780<\/td>\n<td>pfSense CE (prior to 2.8.0 beta) and pfSense Plus builds<\/td>\n<td>Arbitrary command execution via OpenVPN management interface\u00a0<\/td>\n<td>Authenticated access to dashboard with OpenVPN widget privileges\u00a0<\/td>\n<td>8.8 (High)\n<\/td>\n<\/tr>\n<tr>\n<td>CVE-2024-54779<\/td>\n<td>pfSense CE (prior to 2.8.0 beta) and pfSense Plus builds<\/td>\n<td>XML injection causing configuration corruption and persistent XSS\u00a0<\/td>\n<td>Authenticated access to dashboard widget configuration\u00a0<\/td>\n<td>5.4 (Medium)\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Mitigations<\/strong><\/h2>\n<p>Netgate, the company behind pfSense, has addressed these issues in the upcoming pfSense Plus 25.03 and CE 2.8.0 releases.\u00a0<\/p>\n<p>Through the System Patches Package, they have also published fixes for current versions pfSense Plus 24.11 and CE 2.7.2.<\/p>\n<p>Available patches address multiple problems, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>Multiple <a href=\"https:\/\/cybersecuritynews.com\/xss-vulnerabilities-azure\/\" target=\"_blank\" rel=\"noreferrer noopener\">XSS vulnerabilities<\/a> in Dashboard widgets.<\/li>\n<li>OpenVPN management interface command injection.<\/li>\n<li>XSS in AutoConfigBackup backup list.<\/li>\n<li>Potential disclosure of AutoConfigBackup Device Key.<\/li>\n<li>Stored XSS in various system components.<\/li>\n<\/ul>\n<p>According to the <a href=\"https:\/\/blog.brillantit.com\/exploiting-pfsense-xss-command-injection-cloud-hijack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report<\/a>, security researchers disclosed these vulnerabilities to Netgate between November and December 2024, with patches now available in the public pfSense 2.8.0 beta and GitHub master branch.<\/p>\n<p>The Exploit Prediction Scoring System (EPSS) rates the likelihood of exploitation for CVE-2024-54779 at only 0.03%, placing it in the 7th percentile of vulnerabilities. Nevertheless, administrators are strongly encouraged to apply patches immediately.<\/p>\n<p>Users should update to pfSense CE version 2.8.0 or later, or the corresponding version of pfSense Plus, to mitigate these risks.\u00a0<\/p>\n<p>For those unable to update immediately, installing the System Patches Package and applying recommended fixes offers temporary protection.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Equip your SOC team with deep threat analysis for faster response -&gt;\u00a0<a href=\"https:\/\/app.any.run\/plans?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=spring_offer&amp;utm_content=plans&amp;utm_term=190525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get Extra Sandbox Licenses for Free<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/pfsense-firewall-vulnerabilities\/\">Multiple pfSense Firewall Vulnerabilities Let Attackers Inject Malicious Codes<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/pfsense-firewall-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple pfSense Firewall Vulnerabilities Let Attackers Inject Malicious Codes Three critical vulnerabilities in pfSense firewall software that could allow authenticated attackers to inject malicious code, manipulate cloud backups, and potentially achieve remote code execution.\u00a0 The vulnerabilities affect both pfSense Community Edition (CE) prior to version 2.8.0 beta and corresponding pfSense Plus builds. These flaws, CVE-2024-57273, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,724,416,131],"tags":[130],"class_list":["post-4074","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-firewall","category-vulnerabilities","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4074"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4074"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4074\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}