CVE-2023-27253: Netgate Pfsense

High severity, CVSS 8.8. EPSS: 89.5% chance of exploitation in the next 30 days.

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

Affected products

  • Netgate Pfsense: version 2.7.0 only

Published 2023-03-17. Last modified 2026-06-17.