CVE-2019-12585: Apcupsd

Critical severity, CVSS 9.8. EPSS: 5% chance of exploitation in the next 30 days.

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

Affected products

  • Apcupsd Apcupsd: version 0.3.91_5 only
  • Netgate Pfsense: before 2.4.4 (fixed in 2.4.4); version 2.4.4 only

Published 2019-06-03. Last modified 2026-06-17.