cve/2025/CVE-2025-53392.md
2025-09-29 21:09:30 +02:00

1010 B

CVE-2025-53392

Description

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

POC

Reference

Github