Subscribe via feed.

pfSense 2.5.2 Shell Upload

Posted by deepcore on March 5, 2022 – 6:31 pm

This Metasploit module exploits an arbitrary file creation vulnerability in the pfSense HTTP interface (CVE-2021-41282). The vulnerability affects versions 2.5.2 and below and can be exploited by an authenticated user if they have the “WebCfg – Diagnostics: Routing tables” privilege. This module uses the vulnerability to create a web shell and execute payloads with root privileges.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.