Vulnerability record · CVE-2022-29273 · published 22 February 2023
CVE-2022-29273: pfSense WebGUI URL Table Alias XSS
Netgate · Pfsense
pfSense CE through 2.6.0 and pfSense Plus before 22.05 are vulnerable to reflected cross-site scripting in the WebGUI via URL Table Alias URL parameters. An attacker who can lure an authenticated administrator to a crafted link can execute script in the admin's browser session.
Description
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityMedium severity reflected XSS requiring user interaction, with no known in-the-wild exploitation despite a high EPSS score.
What it is
pfSense CE through 2.6.0 and pfSense Plus before 22.05 are vulnerable to reflected cross-site scripting in the WebGUI via URL Table Alias URL parameters. An attacker who can lure an authenticated administrator to a crafted link can execute script in the admin's browser session.
Impact
Successful exploitation lets an attacker run arbitrary script in the context of a logged-in pfSense administrator, enabling session theft or privileged actions through the WebGUI.
Attack surface
Reached over the network through the WebGUI URL Table Alias URL parameter; the CVSS vector indicates no privileges required but user interaction is required, so an authenticated admin must be induced to open a crafted link.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at roughly 0.596 (99th percentile), suggesting elevated likelihood of attempted exploitation; references include a patch and release notes.
What to do
- Upgrade pfSense CE to a release after 2.6.0 or pfSense Plus to 22.05 or later per the vendor advisory
- Apply the fix referenced in the pfSense Redmine issue 13060
- Restrict WebGUI administrative access to trusted management networks
- Warn administrators against opening untrusted links while logged into the WebGUI
Detection
- Review WebGUI access logs for requests containing script-like payloads in URL Table Alias URL parameters
- Monitor for anomalous administrative sessions or unexpected configuration changes following admin browsing
- Alert on crafted links referencing the URL Table Alias page delivered to administrators
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-29273 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29273), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.