CVE-2025-69691
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.
- Affected products
- Pfsense
- Pfsense
- = 2.8.0
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 0.7% (50th percentile)
- Weakness
- CWE-915, CWE-284
- NVD status
- Analyzed
- Published
- 2026-05-08
CVE-2025-69691 at NVD
4 known exploits for CVE-2025-69691
Proof-of-concept code and exploit modules indexed by Sploitus