CVE-2025-53392

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.
Configurations

No configuration.

History

30 Jun 2025, 18:38

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-28 23:15

Updated : 2025-06-30 18:38


NVD link : CVE-2025-53392

Mitre link : CVE-2025-53392

CVE.ORG link : CVE-2025-53392


JSON object : View

Products Affected

No product.

CWE
CWE-36

Absolute Path Traversal