← volver
CVE-2025-34116highCWE-20CWE-306CWE-78

IPFire < 2.19 Core Update 101 proxy.cgi RCE

36Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 8.7epss 1.2%
de la publicación al arma0 días
Publicada en NVD15 jul
metasploit4 may
probabilidad de explotación
1.2%top 35% de las CVE
explotación observada
noninguna fuente lo reporta
A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated attacker can inject arbitrary shell commands through crafted values in the NCSA user creation form fields, leading to command execution with web server privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
IPFire Project · IPFire