CVE-2025-69690
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69690?
CVE-2025-69690 has been assessed to allow code execution, posing a significant security risk.
How do I fix CVE-2025-69690?
To mitigate CVE-2025-69690, ensure that only trusted administrators have access to the module installer and regularly update your pfSense CE software.
Which versions of pfSense are affected by CVE-2025-69690?
CVE-2025-69690 specifically affects Netgate pfSense CE version 2.7.2.
What vulnerability does CVE-2025-69690 exploit?
CVE-2025-69690 exploits the module installer by allowing execution of arbitrary code through a malicious backup file.
Is there a patch available for CVE-2025-69690?
Currently, there is no specific patch mentioned for CVE-2025-69690, but updates to the pfSense software should be monitored for security improvements.