Share
## https://sploitus.com/exploit?id=4E589F28-2934-59B0-9FE0-33B8B35E5433
# CVE-2022-31814

```text


Reworked and optimized exploit script of pfBlockerNG 2.1.4_26 vulnerability

Exploit Title: pfBlockerNG 2.1.4_26 - Remote Code Execution (RCE)
Shodan Results:
https://www.shodan.io/search?query=http.title%3A%22pfSense+-+Login%22+%22Server%3A+nginx%22+%22Set-Cookie%3A+PHPSESSID%3D%22
Date: 5th of September 2022
Exploit Author: IHTeam
Vendor Homepage: https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html
Software Link: https://github.com/pfsense/FreeBSD-ports/pull/1169
Version: 2.1.4_26
Tested on: pfSense 2.6.0
CVE : CVE-2022-31814
Original Advisory: https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/
```