Sploitus

CVE-2025-34176

No indexed exploits for CVE-2025-34176 yet

In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

Affected products
Suricata, Pfsense Ce
Pfsense
< 2.8.0
CVSS 4.0
5.3 MEDIUM
CVSS 3.1
4.3 MEDIUM
EPSS
13.9% (96th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2025-09-09
Attack patterns
CAPEC-126
Entry point
iplist query param
Path
/suricata/suricata_ip_reputation.php
CVE-2025-34176 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-34176 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-34176 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.