Sploitus

CVE-2025-34174

No indexed exploits for CVE-2025-34174 yet

In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions.

Affected products
Pfsense Ce
Pfsense
< 2.8.0
CVSS 3.1
5.4 MEDIUM
EPSS
9.8% (95th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2025-09-09
Attack patterns
CAPEC-592
Entry point
start-day query param
Path
pfSense CE/usr/local/www/status_traffic_totals.php
CVE-2025-34174 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-34174 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-34174 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.