CVE-2023-48123: Netgate Pfsense

High severity, CVSS 8.8. EPSS: 67.8% chance of exploitation in the next 30 days.

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

Affected products

  • Netgate Pfsense: up to and including 2.7.0
  • Netgate Pfsense Plus: up to and including 23.05.1

Published 2023-12-06. Last modified 2026-06-17.