CVE-2025-34312

IPFire versions prior to 2.29 (Core Update 198) containa command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist. When a blacklist is installed the application issues an HTTP POST to /cgi-bin/urlfilter.cgi and interpolates the value of BE_NAME directly into a shell invocation without appropriate sanitation. Crafted input can inject shell metacharacters, leading to arbitrary command execution in the context of the 'nobody' user.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
VulnCheckCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
ipfireipfire
𝑥
< 2.29
ipfireipfire
2.29:core_update183
ipfireipfire
2.29:core_update184
ipfireipfire
2.29:core_update185
ipfireipfire
2.29:core_update186
ipfireipfire
2.29:core_update187
ipfireipfire
2.29:core_update188
ipfireipfire
2.29:core_update189
ipfireipfire
2.29:core_update190
ipfireipfire
2.29:core_update191
ipfireipfire
2.29:core_update192
ipfireipfire
2.29:core_update193
ipfireipfire
2.29:core_update194
ipfireipfire
2.29:core_update195
ipfireipfire
2.29:core_update196
ipfireipfire
2.29:core_update197
𝑥
= Vulnerable software versions