Impact
A stored cross‑site scripting flaw in the Traffic Graphs top‑talkers feature allows an attacker who controls a PTR record and can generate sufficient traffic to appear as a top talker to inject arbitrary JavaScript into the administrator’s browser. The injected script runs in the context of the authenticated admin session and can be used to create new firewall accounts and execute arbitrary operating‑system commands through the management interface.
Affected Systems
The vulnerability affects Netgate’s pfSense CE versions up to 2.8.1 and pfSense Plus versions prior to 26.07. Any system running these releases is susceptible if an attacker can manipulate reverse‑DNS PTR records for IP addresses that generate high traffic.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity; no EPSS data is available and the issue is not listed in CISA KEV, suggesting a low likelihood of widespread exploitation. An attacker must control a PTR record, generate traffic to rank as a top talker, and lure an administrator to the web interface. While the attack requires some control over DNS or the IP space of the victim, the impact, if successful, is the compromise of the firewall’s administrative session, privileged enrolment of new users, and the execution of arbitrary system commands.
OpenCVE Enrichment