Vulnerability record · CVE-2018-4019 · published 3 December 2018
CVE-2018-4019: Netgate pfSense CE command injection in powerd_normal_mode parameter
Netgate · Pfsense
Netgate pfSense CE 2.4.4-RELEASE fails to sanitize the powerd_normal_mode parameter of a specific POST request, allowing OS command injection. An attacker who can send authenticated POST requests to the administration web interface can execute arbitrary commands on the firewall. This matters because pfSense is a perimeter device, so command execution there can expose or disrupt the whole protected network.
Description
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_normal_mode` parameter.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityAuthenticated remote command execution on a perimeter firewall with a high EPSS score and public exploit detail, though exploitation requires valid admin credentials and no KEV listing exists.
What it is
Netgate pfSense CE 2.4.4-RELEASE fails to sanitize the powerd_normal_mode parameter of a specific POST request, allowing OS command injection. An attacker who can send authenticated POST requests to the administration web interface can execute arbitrary commands on the firewall. This matters because pfSense is a perimeter device, so command execution there can expose or disrupt the whole protected network.
Impact
An attacker gains arbitrary command execution on the pfSense system with the privileges of the web interface process, enabling full compromise of the firewall host and anything it protects.
Attack surface
Reached over the network through the administration web interface via a crafted POST request; the CVSS vector (AV:N/PR:H/UI:N) indicates valid administrative authentication is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high (0.48721, 98.8th percentile), and the only references are Talos advisory entries tagged Exploit, indicating public exploit detail exists but no confirmed in-the-wild activity is recorded here.
What to do
- Upgrade pfSense CE past 2.4.4-RELEASE to a release that fixes the powerd_normal_mode command injection.
- Restrict administrative web interface access to trusted management networks and never expose it to the internet.
- Enforce strong unique admin credentials and multi-factor authentication where supported to limit abuse of authenticated POST access.
- Audit and remove unnecessary admin accounts, and monitor for unexpected changes to powerd or system configuration.
- Where feasible, apply network segmentation so a compromised firewall host cannot freely reach internal segments.
Detection
- Review web server and system logs for POST requests to the administration interface containing powerd_normal_mode with shell metacharacters.
- Alert on unexpected child processes or shell invocations spawned by the pfSense web interface process.
- Monitor for unauthorized changes to powerd settings or system configuration files on pfSense hosts.
- Correlate administrative login events with subsequent command execution or configuration changes on the firewall.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2018-0690 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2018-0690 | ExploitThird Party Advisory |
Track CVE-2018-4019 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-4019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.