CVE-2025-34174
In pfSense CEÂ /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions.
- Affected products
- Pfsense Ce
- Pfsense
- < 2.8.0
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 9.8% (95th percentile)
- Weakness
- CWE-79
- NVD status
- Analyzed
- Published
- 2025-09-09
- Attack patterns
- CAPEC-592
- Entry point
- start-day query param
- Path
- pfSense CE/usr/local/www/status_traffic_totals.php
CVE-2025-34174 at NVD
No indexed exploits for CVE-2025-34174 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-34174 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.