CVE-2020-21487: Netgate Pfsense

Critical severity, CVSS 9.6. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.

Affected products

  • Netgate Pfsense: version 2.4.4 only
  • Netgate Pfsense Acme Package: version 0.6.3 only

Published 2023-04-04. Last modified 2026-06-17.