CVE-2025-69690Discl(pfsense / pfsense)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for pfsense pfsense systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pfsense

Threat summary

  • Exploit tooling references are present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • Technical details provided in 1 signal
  • Discl: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
pfsense

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-10: 1Exploit Tool / Code · 2026-05-10: 1Technical Details · 2026-05-10: 105-10
Signal classification1 categories
Discl
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Discl

    CVE-2025-69690 Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands prope… https://www.cve.org/CVERecord?id=CVE-2025-69690

    Post summary

    The text discloses a code execution vulnerability (CVE-2025-69690) in Netgate pfSense CE 2.7.2, detailing the exploit method via a serialized PHP object, but it does not provide a PoC, active exploitation evidence, or patch information.

    00020862
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppfsensepfsense2.7.2--

Explore more