IPfire is an open-source firewall and network security appliance that serves as a self-hosted alternative to commercial gateway devices, presenting a focused but network-critical attack surface. Vulnerabilities affecting the platform concentrate in web-management and command-injection vectors characteristic of network appliances, with recurring weakness classes including cross-site scripting, OS command injection, and SQL injection that reflect the appliance's role in parsing untrusted network traffic and user input. The exposure recurs across the single IPfire product line and frequently acquires public exploit tooling, making disclosed flaws of particular concern in environments where the appliance is internet-facing or manages critical network segments. Defenders should prioritize patches for this vendor given the appliance's direct role in perimeter security and the exploit availability that follows disclosure; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipfire over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33393HIGH lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could pote | Jun 9, 2021 | 8.8 | 77 | NO | YES |
CVE-2017-9757HIGH IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited directly by authenticated user | Jun 19, 2017 | 8.8 | 60 | NO | YES |
CVE-2025-34311HIGH IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' v | Oct 28, 2025 | 8.8 | 35 | NO | NO |
CVE-2018-16232HIGH An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated user with privileges for the affe | Oct 17, 2018 | 8.8 | 31 | NO | NO |
CVE-2025-34312HIGH IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user v | Oct 28, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-34309MEDIUM IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code | Oct 28, 2025 | 5.4 | 22 | NO | NO |
CVE-2025-34304MEDIUM IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL query used when viewing OpenVPN co | Oct 28, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-50974MEDIUM The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell co | Aug 26, 2025 | 6.5 | 22 | NO | NO |
CVE-2019-25399MEDIUM IPFire 2.21 Core Update 127 contains multiple stored cross-site scripting vulnerabilities in the extrahd.cgi script that allow attackers to inject malicious scripts through the FS, | Feb 18, 2026 | 6.4 | 21 | NO | NO |
CVE-2019-25398MEDIUM IPFire 2.21 Core Update 127 contains multiple cross-site scripting vulnerabilities in the ovpnmain.cgi script that allow attackers to inject malicious scripts through VPN configura | Feb 18, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipfire.
Media articles that mention a CVE ID that affects a product developed by Ipfire — matched by CVE ID, not by vendor name.