CVE-2023-27253: Netgate Pfsense
High severity, CVSS 8.8. EPSS: 89.5% chance of exploitation in the next 30 days.
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
Affected products
- Netgate Pfsense: version 2.7.0 only
Published 2023-03-17. Last modified 2026-06-17.