CVE-2023-42326: Netgate Pfsense

High severity, CVSS 8.8. EPSS: 64% chance of exploitation in the next 30 days.

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

Affected products

  • Netgate Pfsense: up to and including 2.7.0
  • Netgate Pfsense Plus: up to and including 23.05.1

Published 2023-11-14. Last modified 2026-06-17.