pfSense 2.5.2 contains a cross-site scripting vulnerability in interfaces_groups_edit.php. A crafted payload injected into the $pconfig variable can cause arbitrary web scripts or HTML to be executed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a working exploit for CVE-2024-46538, a stored XSS vulnerability in pfSense v2.5.2. The main exploit script (CVE-2024-46538.py) is a Python tool that automates authentication to a target pfSense instance and injects a malicious JavaScript payload into the 'members[]' parameter of the interfaces_groups_edit.php endpoint. The payload can be a custom JavaScript URL or the included mal.js file. When an administrator later visits the affected page, the JavaScript executes in their browser context. The included mal.js script demonstrates how the XSS can be leveraged to send a POST request to diag_command.php, executing arbitrary commands (such as 'id') on the pfSense system. The exploit requires valid credentials for a user with sufficient privileges to edit interface groups. The repository includes a README with setup instructions, usage examples, and a technical analysis of the vulnerability. The requirements.txt lists the necessary Python dependencies. The exploit demonstrates a full attack chain from XSS to command execution, making it operational and effective for testing or demonstration purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.