Impact
A cross‑site scripting flaw exists in the captive_portal_status.widget.php file of Netgate pfSense. The flaw allows a remote attacker to inject and execute arbitrary code within the context of the web interface, potentially leading to full compromise of the control plane. The weakness is an unsanitized input endpoint, matching the common XSS threat model. It is mapped to CWE‑79.
Affected Systems
The vulnerability impacts Netgate pfSense Plus releases up to 26.03 and pfSense Community Edition releases up to 2.8.1. All installations that expose the captive portal status widget are affected. Administrators using versions beyond these thresholds are considered non‑affected.
Risk and Exploitability
The flaw is remotely exploitable via the web UI, requiring only that an attacker can access the captive_portal_status.widget.php endpoint. No local privilege or elevated authentication is needed. The CVSS baseline score is 5.4, and EPSS < 1% indicates modest exploitation probability; KEV not listed suggests limited exploitation in the wild. Nonetheless, the ability to execute code remotely warrants moderate risk.
OpenCVE Enrichment