We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53392



Description

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

Reserved 2025-06-28 | Published 2025-06-28 | Updated 2025-06-28 | Assigner mitre


MEDIUM: 5.0CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Problem types

CWE-36 Absolute Path Traversal

Product status

Default status
unknown

2.8.0
affected

References

github.com/skraft9/pfsense-security-research

cve.org (CVE-2025-53392)

nvd.nist.gov (CVE-2025-53392)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53392

Support options

Helpdesk Chat, Email, Knowledgebase