CVE-2019-16701: OS Command Injection
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.execphp call containing shell metacharacters in a parameter value.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16701?
CVE-2019-16701 is a vulnerability in pfSense versions 2.3.4 through 2.4.4-p3 that allows remote code injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.
How severe is CVE-2019-16701?
CVE-2019-16701 has a severity rating of 8.8 (Critical).
Which software versions are affected by CVE-2019-16701?
pfSense versions 2.3.4 through 2.4.4-p3 are affected by CVE-2019-16701.
How can remote code injection occur in pfSense?
Remote code injection can occur in pfSense through a methodCall XML document with a pfsense.exec_php call that contains shell metacharacters in a parameter value.
What is the Common Weakness Enumeration (CWE) ID related to CVE-2019-16701?
CVE-2019-16701 is associated with CWE-94 and CWE-78 vulnerabilities.