Aller au contenu

Fiche vulnérabilité

CVE-2025-34312 : faille élevée ipfire ipfire (CVSS 8.8)

Description

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist. When a blacklist is installed the application issues an HTTP POST to /cgi-bin/urlfilter.cgi and interpolates the value of BE_NAME directly into a shell invocation without appropriate sanitation. Crafted input can inject shell metacharacters, leading to arbitrary command execution in the context of the 'nobody' user.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
28 oct. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • ipfire ipfire

Références

Rechercher une autre vulnérabilité dans la base CVE