Vulnerability record · CVE-2018-4021 · published 3 December 2018
CVE-2018-4021: pfSense CE admin interface command injection via powerd_battery_mode
Netgate · Pfsense
Netgate pfSense CE 2.4.4-RELEASE fails to sanitize the powerd_battery_mode POST parameter, allowing OS command injection. An authenticated administrator can execute arbitrary commands on the firewall, which is a high-value network device.
Description
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_battery_mode` POST parameter.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRequires admin credentials but yields full command execution on a perimeter firewall, and public exploit material plus very high EPSS raise the risk.
What it is
Netgate pfSense CE 2.4.4-RELEASE fails to sanitize the powerd_battery_mode POST parameter, allowing OS command injection. An authenticated administrator can execute arbitrary commands on the firewall, which is a high-value network device.
Impact
An attacker with admin access gains arbitrary command execution on the pfSense system, enabling full compromise of the firewall and any traffic or credentials it handles.
Attack surface
Reached over the network through the administration web interface via a crafted POST request; the attacker must already hold valid admin credentials, and no user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.7221, 99.4th percentile) and the Talos reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade pfSense CE to a release later than 2.4.4-RELEASE that fixes the powerd_battery_mode command injection.
- Restrict access to the admin web interface to trusted management networks and disable WAN-side administration.
- Enforce strong unique admin credentials and MFA where supported to limit credential-based reach.
- Audit admin accounts and rotate credentials if compromise is suspected.
Detection
- Review web server and system logs for POST requests containing powerd_battery_mode with shell metacharacters.
- Alert on unexpected child processes spawned by the web GUI or PHP-FPM on the firewall.
- Monitor for outbound connections or new files/accounts on pfSense hosts that deviate from baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2018-0690 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2018-0690 | ExploitThird Party Advisory |
Track CVE-2018-4021 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-4021), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.