netgate pfsense CVE-2018-16055 is a vulnerability in Netgate Pfsense
Published on September 26, 2018

An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of the variables. This allows an authenticated WebGUI user with privileges for the affected page to execute commands in the context of the root user when submitting a request to relinquish a DHCP lease for an interface which is configured to obtain its address via DHCP.

NVD


Products Associated with CVE-2018-16055

Want to know whenever a new CVE is published for Netgate Pfsense? stack.watch will email you.

 

Exploit Probability

EPSS
13.50%
Percentile
94.10%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.