Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ipfire

First CVE: Jun 19, 2017Active for: 9 yearsTotal CVEs: 32
39.3
VTI Score
Medium

IPfire is an open-source firewall and network security appliance that serves as a self-hosted alternative to commercial gateway devices, presenting a focused but network-critical attack surface. Vulnerabilities affecting the platform concentrate in web-management and command-injection vectors characteristic of network appliances, with recurring weakness classes including cross-site scripting, OS command injection, and SQL injection that reflect the appliance's role in parsing untrusted network traffic and user input. The exposure recurs across the single IPfire product line and frequently acquires public exploit tooling, making disclosed flaws of particular concern in environments where the appliance is internet-facing or manages critical network segments. Defenders should prioritize patches for this vendor given the appliance's direct role in perimeter security and the exploit availability that follows disclosure; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
5.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ipfire over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2017
9 years ago
Most Recent CVE
Feb 18, 2026
157 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-33393HIGH
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could pote
Jun 9, 20218.877NOYES
CVE-2017-9757HIGH
IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited directly by authenticated user
Jun 19, 20178.860NOYES
CVE-2025-34311HIGH
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' v
Oct 28, 20258.835NONO
CVE-2018-16232HIGH
An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated user with privileges for the affe
Oct 17, 20188.831NONO
CVE-2025-34312HIGH
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user v
Oct 28, 20258.829NONO
CVE-2025-34309MEDIUM
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code
Oct 28, 20255.422NONO
CVE-2025-34304MEDIUM
IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL query used when viewing OpenVPN co
Oct 28, 20256.522NONO
CVE-2025-50974MEDIUM
The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell co
Aug 26, 20256.522NONO
CVE-2019-25399MEDIUM
IPFire 2.21 Core Update 127 contains multiple stored cross-site scripting vulnerabilities in the extrahd.cgi script that allow attackers to inject malicious scripts through the FS,
Feb 18, 20266.421NONO
CVE-2019-25398MEDIUM
IPFire 2.21 Core Update 127 contains multiple cross-site scripting vulnerabilities in the ovpnmain.cgi script that allow attackers to inject malicious scripts through VPN configura
Feb 18, 20266.121NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
84%
16%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network32 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (25.0%)
Unknown0 (0.0%)
Required24 (75.0%)
Privileges Required
Low25 (78.1%)
High1 (3.1%)
None6 (18.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
6.2% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ipfire.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ipfire — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ipfire's Products

View all 3 CNAs →

Top CWEs