CVE-2025-69691
EUVD-2025-20973908.05.2026, 07:16
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pfsense | pfsense | 2.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration