← Vulnerability feed

Vulnerability record · CVE-2023-27253 · published 17 March 2023

CVE-2023-27253: pfSense restore_rrddata() command injection via crafted XML config

Netgate · Pfsense

Netgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to the config.xml restore component and cause arbitrary commands to run on the firewall. Because pfSense is a perimeter device, successful exploitation can compromise network security controls.

8.8 CVSS 3.1 High EPSS 90% · top 0.2% CWE-91 · XML injection
8.8CVSS 3.1 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with high EPSS and a public advisory make this a serious authenticated command injection on a perimeter firewall, though it requires valid credentials and is not in KEV.

What it is

Netgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to the config.xml restore component and cause arbitrary commands to run on the firewall. Because pfSense is a perimeter device, successful exploitation can compromise network security controls.

Impact

An attacker with a valid account gains arbitrary command execution on the pfSense appliance, with high impact to confidentiality, integrity and availability. This can lead to full device compromise and potential lateral movement into protected networks.

Attack surface

Reached over the network through the config.xml restore functionality, per the CVSS vector AV:N. The attacker must be authenticated with low privileges (PR:L); no user interaction is required (UI:N).

Exploitation

The record shows no CISA KEV listing and no ransomware association, but EPSS is very high at 0.895 (99.8th percentile), indicating elevated likelihood of exploitation activity. References include a public Packet Storm advisory and vendor patch, but no explicit proof-of-concept tag is present.

What to do

  • Upgrade pfSense to a version containing the fix referenced in commit ca80d18493f8f91b21933ebd6b714215ae1e5e94.
  • Restrict access to the pfSense webGUI and config restore functionality to trusted management networks only.
  • Apply least privilege to pfSense accounts and remove or disable unused accounts that could reach the restore feature.
  • Monitor and validate any XML configuration files restored to the appliance before import.
  • Review vendor advisory redmine.pfsense.org/issues/13935 for any additional hardening guidance.

Detection

  • Alert on unexpected child processes spawned by the pfSense webGUI or config restore components.
  • Monitor pfSense audit and system logs for config.xml restore or RRD data restore actions outside change windows.
  • Inspect uploaded XML files for shell metacharacters or unexpected command strings before restore.
  • Watch for outbound connections or new processes on the firewall that do not match normal appliance behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27253 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16915Netgate pfsense path traversal vulnerabilityAn issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e…EPSS 3.7%9.8CVE-2019-12585Apcupsd os command injection vulnerabilityApcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.EPSS 5.0%9.6CVE-2020-21487Netgate pfsense cross-site scripting vulnerabilityCross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFol…EPSS 0.67%8.8CVE-2023-48123pfSense web GUI packet_capture.php remote code executionpfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.p…EPSS 68%analysed8.8CVE-2023-42326pfSense WebGUI GIF/GRE Interface Command InjectionNetgate pfSense 2.7.0 contains a command injection flaw in the interfaces_gif_edit.php and interfaces_gre_edit.php WebGUI components. A remote attack…EPSS 64%analysed8.8CVE-2022-24299Netgate pfsense improper input validation vulnerabilityImproper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…EPSS 1.9%8.8CVE-2022-26019Netgate pfsense path traversal vulnerabilityImproper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions …EPSS 4.5%8.8CVE-2019-16667pfSense diag_command.php CSRF enables OS command executiondiag_command.php in pfSense 2.4.4-p3 is vulnerable to cross-site request forgery through the txtCommand or txtRecallBuffer fields, allowing an attack…EPSS 55%analysed

Source: NIST National Vulnerability Database (record CVE-2023-27253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.