Netgate develops firewall, network gateway, and security appliance software—principally pfSense in its open-source, community, and commercial variants—that serves as a perimeter defense point for small to medium-sized networks and is more prominent than most single-product vendors in the landscape. Vulnerabilities affecting the vendor cluster around web-interface and command-execution attack surfaces: cross-site scripting, OS command injection, path traversal, and cross-site request forgery recur across its product line and reflect the exposed administrative interface and privilege-escalation risks inherent to gateway appliances. A meaningful share of the vendor's disclosures reach critical severity, and vulnerabilities in this product family have a marked tendency to acquire public exploit tooling, making timely patching essential for operators of internet-exposed or management-accessible instances. Defenders should prioritize tracking pfSense updates and inventory deployed instances and firmware versions, particularly for versions approaching or in end-of-life; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netgate over time
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31814CRITICAL pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected. | Sep 5, 2022 | 9.8 | 93 | NO | YES |
CVE-2023-27253HIGH A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the cont | Mar 17, 2023 | 8.8 | 84 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2019-16667HIGH diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces | Sep 26, 2019 | 8.8 | 69 | NO | YES |
CVE-2023-42326HIGH An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components. | Nov 14, 2023 | 8.8 | 64 | NO | NO |
CVE-2019-12347MEDIUM In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability | May 29, 2019 | 6.1 | 64 | NO | YES |
CVE-2018-4021HIGH An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this | Dec 3, 2018 | 7.2 | 63 | NO | NO |
CVE-2015-2295MEDIUM Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication | Apr 10, 2015 | 6.8 | 63 | NO | YES |
CVE-2024-46538MEDIUM A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at | Oct 22, 2024 | 4.8 | 62 | NO | NO |
CVE-2023-48123HIGH An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file | Dec 6, 2023 | 8.8 | 58 | NO | NO |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netgate.
Media articles that mention a CVE ID that affects a product developed by Netgate — matched by CVE ID, not by vendor name.