CVE-2022-31814 is a critical unauthenticated remote command execution vulnerability in pfBlockerNG, a popular pfSense plugin, up to version 2.1.4_26. The vulnerability arises from improper sanitization of the HTTP Host header in /usr/local/www/pfblockerng/www/index.php, which is passed directly to the PHP exec() function. This allows remote attackers to inject arbitrary OS commands, executed as root, by crafting malicious Host headers. The vulnerability is exploitable despite some character restrictions, and proof-of-concept code demonstrates the ability to backdoor pfSense systems.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python exploit for CVE-2022-31814 affecting pfSense systems with pfBlockerNG installed. The repository contains only two files: a README describing usage and one executable script, pfsense.py. The Python script is the sole entry point and uses requests, argparse, threading, urllib.parse, and time. It disables TLS certificate warnings and forces HTTPS to each supplied target. Operational flow: for each target listed in an operator-provided file, the script spawns a thread and instantiates PfSenseExploit. It first requests /pfblockerng/www/index.php to check whether pfBlockerNG appears present. It then exploits the vulnerable endpoint by sending a malicious Host header containing a shell command. That command echoes a base64-encoded PHP payload, decodes it with python3.8 -m base64 -d, and pipes it into php so that a web shell is written to /usr/local/www/system_advanced_control.php. The script verifies success by requesting the shell with ?c=id and checking for uid=0(root) gid=0(wheel), indicating root-level command execution. It then executes the attacker-supplied command via the same shell endpoint and finally issues rm /usr/local/www/system_advanced_control.php to remove the artifact. Main exploit capability: authenticated interaction is not required in the code; it is a remote web/network exploit that achieves arbitrary command execution by planting a temporary PHP web shell. The payload is basic and hardcoded, making the exploit operational rather than heavily weaponized. Notable fingerprintable artifacts include the vulnerable path /pfblockerng/www/index.php, the dropped shell /usr/local/www/system_advanced_control.php, and follow-on requests to /system_advanced_control.php?c=<command>. The script is not a scanner-only tool; it performs full exploitation and cleanup.
This repository contains a Python exploit script (pfsense.py) targeting CVE-2022-31814, a vulnerability in pfSense firewalls with the pfBlockerNG package installed. The exploit works by checking for the presence of pfBlockerNG, uploading a base64-encoded PHP web shell to the target, executing an arbitrary command provided by the user, and then deleting the shell to cover tracks. The script is multithreaded and can target multiple pfSense instances by reading a list of URLs from a file. The main exploit capabilities are remote command execution as root via a web shell. The script interacts with specific endpoints on the target, notably /pfblockerng/www/index.php for the initial check and shell upload, and /system_advanced_control.php for command execution and shell deletion. The repository consists of two files: a README.md with usage instructions and pfsense.py containing the exploit logic. The exploit is operational, providing a working payload and automated cleanup.
This repository contains a single Metasploit module targeting pfSense systems with the pfBlockerNG plugin (version 2.1.4_26 and below). The exploit leverages an unauthenticated remote code execution (RCE) vulnerability (CVE-2022-31814) in the pfBlockerNG plugin's web interface. The module uploads a PHP webshell to the target system by exploiting improper input handling in the /pfblockerng/www/index.php endpoint. Once the webshell is uploaded to /usr/local/www/<random>.php, the module can execute arbitrary commands as root, either directly or by staging a more complex payload (such as a reverse shell). The exploit is fully weaponized, supporting both command execution and staged payloads, and is integrated into the Metasploit framework. The only file in the repository is the Metasploit module itself, written in Ruby.
This repository contains a Python proof-of-concept exploit for CVE-2022-31814, a remote code execution vulnerability in pfBlockerNG <= 2.1.4_26 on pfSense. The main file, CVE-2022-31814.py, allows an unauthenticated attacker to upload a PHP web shell to the target system by abusing the Host header in HTTP requests to the pfBlockerNG web interface. The exploit checks for the presence of pfBlockerNG, attempts multiple payloads to upload the shell, and then provides an interactive shell for executing arbitrary commands as root. The shell is deleted after use. The repository also includes a README.md with usage instructions and a requirements.txt specifying the 'requests' Python library. The exploit targets network-accessible pfSense systems running the vulnerable pfBlockerNG version, and the attack vector is fully remote over HTTP.
This repository contains a Python proof-of-concept exploit for an unauthenticated remote code execution (RCE) vulnerability in pfBlockerNG <= 2.1.4_26. The main file, exploit.py, allows an attacker to target a single pfBlockerNG instance or scan multiple targets in parallel. The exploit works by uploading a base64-encoded PHP shell to the target's web directory, then executing arbitrary commands via HTTP GET requests to the shell. It supports both single-command execution and an interactive shell mode. After exploitation, the script deletes the shell to clean up. The exploit is network-based, requiring only HTTP(S) access to the target. The repository also includes a requirements.txt for dependencies and a README.md with detailed usage instructions. No CVE is referenced, but the exploit specifically targets pfBlockerNG <= 2.1.4_26 on Linux-based systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.