← Vulnerability feed

Vulnerability record · CVE-2019-16667 · published 26 September 2019

CVE-2019-16667: pfSense diag_command.php CSRF enables OS command execution

Netgate · Pfsense

diag_command.php in pfSense 2.4.4-p3 is vulnerable to cross-site request forgery through the txtCommand or txtRecallBuffer fields, allowing an attacker to make a logged-in administrator execute arbitrary OS commands. The flaw stems from csrf_callback() returning a "CSRF token expired" error with a Try Again button when the token is missing, which weakens the CSRF protection. It matters because a firewall/edge device command execution can lead to full compromise of the appliance.

8.8 CVSS 3.1 High EPSS 55% · top 1.0% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 6.8
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 8.8 with network reachability and high EPSS plus public exploit references make this a serious risk for exposed pfSense management interfaces, though it requires an authenticated admin and user interaction.

What it is

diag_command.php in pfSense 2.4.4-p3 is vulnerable to cross-site request forgery through the txtCommand or txtRecallBuffer fields, allowing an attacker to make a logged-in administrator execute arbitrary OS commands. The flaw stems from csrf_callback() returning a "CSRF token expired" error with a Try Again button when the token is missing, which weakens the CSRF protection. It matters because a firewall/edge device command execution can lead to full compromise of the appliance.

Impact

An attacker who lures an authenticated pfSense administrator into a crafted request can execute arbitrary OS commands on the firewall with the admin's privileges, potentially leading to full device compromise and network-level impact.

Attack surface

The flaw is reachable over the network via a crafted web request to diag_command.php; it requires the victim to be authenticated to pfSense and to be induced into triggering the request (user interaction), as reflected by the CVSS vector AV:N/PR:N/UI:R.

Exploitation

CVE-2019-16667 is not listed in CISA KEV, but EPSS is high (0.54541, ~99th percentile) and public references include an Exploit-tagged third-party advisory, indicating exploit code or proof-of-concept is publicly available.

What to do

  • Upgrade pfSense to a version later than 2.4.4-p3 that fixes the CSRF handling in diag_command.php.
  • Restrict administrative webGUI access to trusted management networks and avoid exposing it to the internet.
  • Require administrators to log out of pfSense before browsing untrusted sites and use a separate browser profile for appliance management.
  • Apply CSRF protections at the reverse proxy or WAF layer for the pfSense management interface where feasible.

Detection

  • Monitor web server or firewall logs for POST requests to diag_command.php with txtCommand or txtRecallBuffer parameters from unexpected sources.
  • Alert on pfSense admin sessions that generate command-execution activity shortly after a cross-site request pattern.
  • Review authentication and audit logs for anomalous admin actions or unexpected command execution on the appliance.
  • Hunt for known exploit payload strings or referer patterns associated with the public PoC against diag_command.php.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-16667 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16915Netgate pfsense path traversal vulnerabilityAn issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e…EPSS 3.7%9.8CVE-2019-12585Apcupsd os command injection vulnerabilityApcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.EPSS 5.0%9.6CVE-2020-21487Netgate pfsense cross-site scripting vulnerabilityCross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFol…EPSS 0.67%8.8CVE-2023-48123pfSense web GUI packet_capture.php remote code executionpfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.p…EPSS 68%analysed8.8CVE-2023-42326pfSense WebGUI GIF/GRE Interface Command InjectionNetgate pfSense 2.7.0 contains a command injection flaw in the interfaces_gif_edit.php and interfaces_gre_edit.php WebGUI components. A remote attack…EPSS 64%analysed8.8CVE-2023-27253pfSense restore_rrddata() command injection via crafted XML configNetgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to…EPSS 90%analysed8.8CVE-2022-24299Netgate pfsense improper input validation vulnerabilityImproper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…EPSS 1.9%8.8CVE-2022-26019Netgate pfsense path traversal vulnerabilityImproper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions …EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2019-16667), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.