CVE-2025-69690
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.
- Affected products
- Pfsense Ce
- Pfsense
- = 2.7.2
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-915, CWE-502
- NVD status
- Analyzed
- Published
- 2026-05-08
CVE-2025-69690 at NVD
4 known exploits for CVE-2025-69690
Proof-of-concept code and exploit modules indexed by Sploitus