
6/10 searchsploit "pfsense 2.1.3"One hit: CVE-2014-4688 Authenticated RCE via unsanitized GET param in status_rrd_graph_img.phpExploitDB script is broken. Use the fixed PoC from GitHub (jaydenblair/CVE-2014-4688-pfsense).
Post summary
The post announces that a corrected PoC for CVE-2014-4688 in pfsense 2.1.3 is available on GitHub, detailing an authenticated RCE via an unsanitized GET parameter. No evidence of active exploitation or vendor patches is provided.
