Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Multiple pfSense Firewall Vulnerabilities Let Attackers Inject Malicious Codes

Three critical vulnerabilities have been identified in pfSense firewall software, affecting both the Community Edition (CE) and pfSense Plus builds prior to version 2.8.0 beta. These vulnerabilities, CVE-2024-57273, CVE-2024-54780, and CVE-2024-54779,…

Three critical vulnerabilities have been identified in pfSense firewall software, affecting both the Community Edition (CE) and pfSense Plus builds prior to version 2.8.0 beta. These vulnerabilities, CVE-2024-57273, CVE-2024-54780, and CVE-2024-54779, could allow authenticated attackers to execute malicious actions, including code injection, manipulation of cloud backups, and potential remote code execution.

CVE-2024-57273: Affects the Automatic Configuration Backup (ACB) service. Enables the hijacking of cloud backup keys, leading to backup deletion, stored cross-site scripting (XSS) attacks, and information leakage. Exploitation requires an accessible SSH server and ACB configuration. CVE-2024-54780: Involves command injection in the OpenVPN widget. Allows attackers to inject arbitrary OpenVPN management commands via the unsanitized remipp parameter. CVE-2024-54779: Enables XML injection in dashboard widgets via the widgetkey parameter, potentially causing configuration file corruption and persistent XSS attacks.

The vulnerabilities stem from inadequate sanitization of inputs, allowing attackers to manipulate system configurations and execute unauthorized commands.

Netgate has addressed these vulnerabilities in the upcoming pfSense Plus 25.03 and CE 2.8.0 releases. Fixes for current versions, pfSense Plus 24.11 and CE 2.7.2, are available through the System Patches Package. Patches address issues such as:

CVE-2024-57273: Affects the Automatic Configuration Backup (ACB) service.
Hazel Caldwell · Thehackingpost

Multiple XSS vulnerabilities in Dashboard widgets. OpenVPN management interface command injection. XSS in AutoConfigBackup backup list. Potential disclosure of AutoConfigBackup Device Key. Stored XSS in various system components.

Security researchers reported these vulnerabilities to Netgate between November and December 2024, and patches are now available in the public pfSense 2.8.0 beta and GitHub master branch. The Exploit Prediction Scoring System (EPSS) rates the likelihood of exploitation for CVE-2024-54779 at 0.03%, but it is strongly recommended for administrators to apply patches immediately.

Advertisement

Users should update to pfSense CE version 2.8.0 or later, or the corresponding version of pfSense Plus. For those unable to update immediately, installing the System Patches Package provides temporary protection.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories