CVE-2019-16701: Netgate Pfsense
High severity, CVSS 8.8. EPSS: 19.6% chance of exploitation in the next 30 days.
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.
Affected products
- Netgate Pfsense: from 2.3.4, before 2.4.4 (fixed in 2.4.4); version 2.4.4 only
Published 2019-09-25. Last modified 2026-06-17.