Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15584 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter. |
Fri, 13 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgate
Netgate pfsense Ce Netgate pfsense Plus |
|
| CPEs | cpe:2.3:a:netgate:pfsense_ce:*:*:*:*:*:*:*:* cpe:2.3:a:netgate:pfsense_plus:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgate
Netgate pfsense Ce Netgate pfsense Plus |
Sat, 17 May 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 17 May 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 14 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Wed, 14 May 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-20T14:29:04.503Z
Reserved: 2024-12-06T00:00:00.000Z
Link: CVE-2024-54780
Updated: 2025-05-14T15:00:23.940Z
Status : Analyzed
Published: 2025-05-14T14:15:26.053
Modified: 2025-06-13T13:03:51.367
Link: CVE-2024-54780
No data.
OpenCVE Enrichment
No data.
EUVD