pfSense versions prior to 2.1.4 are vulnerable to command injection, allowing remote authenticated users to execute arbitrary commands on the system. The vulnerability exists in multiple scripts: diag_dns.php (via the hostname parameter in a Create Alias action), diag_smart.php (via the smartmonemail parameter), and status_rrd_graph_img.php (via the database parameter). Unsanitized user input is passed to system commands, enabling attackers to inject and execute arbitrary shell commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python3 exploit script and a README. The exploit targets CVE-2014-4688 in pfSense <= 2.1.3, an authenticated command injection in `status_rrd_graph_img.php` via the `database` GET parameter. Workflow: (1) create a requests Session with TLS verification disabled (self-signed friendly) and suppress urllib3 warnings; (2) GET `https://RHOST/index.php` and scrape `csrfMagicToken` from HTML; (3) POST login form fields (`__csrf_magic`, `usernamefld`, `passwordfld`) to authenticate and obtain cookies; (4) build a reverse-shell command (Python one-liner) and octal-encode it; (5) send a GET request to `status_rrd_graph_img.php` with `database=queues;printf '<octal>'|sh` to execute the payload. The script uses a short timeout and treats a timeout/exception as likely success (shell caught). No scanning/detection logic—this is an operational RCE-to-reverse-shell PoC requiring valid credentials and outbound connectivity from the target to the attacker.
This repository contains a working exploit for CVE-2014-4688, a command injection vulnerability in pfSense <= 2.1.3 (FreeBSD). The main file, 'exploit.js', is a Node.js script that automates the exploitation process. It first authenticates to the pfSense web interface using provided credentials, retrieves a CSRF token, and then performs a command injection via the 'status_rrd_graph_img.php' endpoint. The injected command is a Python one-liner that opens a reverse shell from the target pfSense system to the attacker's machine (10.10.16.7:443). The script also sets up a local listener to receive the shell. The exploit requires valid credentials and network access to the pfSense web interface. The repository structure is simple, with a README providing usage instructions and a single exploit script. The exploit is operational and provides a real reverse shell if successful.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.