Sploitus

CVE-2025-53392

1 known exploit for CVE-2025-53392

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

Affected products
Pfsense Ce
Pfsense
= 2.8.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
1.8% (77th percentile)
Weakness
CWE-36
NVD status
Analyzed
Published
2025-06-28
CVE-2025-53392 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-53392

Proof-of-concept code and exploit modules indexed by Sploitus