CVE-2025-53392
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.
- Affected products
- Pfsense Ce
- Pfsense
- = 2.8.0
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.8% (77th percentile)
- Weakness
- CWE-36
- NVD status
- Analyzed
- Published
- 2025-06-28
CVE-2025-53392 at NVD
1 known exploit for CVE-2025-53392
Proof-of-concept code and exploit modules indexed by Sploitus