Vulnerability record · CVE-2023-48123 · published 6 December 2023
CVE-2023-48123: pfSense web GUI packet_capture.php remote code execution
Netgate · Pfsense
pfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.php. The flaw is in the web GUI and carries a CVSS 3.1 base score of 8.8 (HIGH). The record gives no CWE detail beyond 'insufficient information', so the exact root cause is not stated.
Description
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution on a perimeter firewall with a CVSS of 8.8 and very high EPSS, though it requires low privileges and no public exploit is confirmed in the record.
What it is
pfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.php. The flaw is in the web GUI and carries a CVSS 3.1 base score of 8.8 (HIGH). The record gives no CWE detail beyond 'insufficient information', so the exact root cause is not stated.
Impact
An attacker with the required privileges can run arbitrary code on the firewall, gaining full control of confidentiality, integrity and availability of the device. Because pfSense is a perimeter appliance, compromise can expose or redirect network traffic.
Attack surface
Reachable over the network via the web GUI (AV:N, AC:L), requiring low privileges (PR:L) and no user interaction (UI:N). The crafted request targets packet_capture.php, so the attacker needs at least an authenticated GUI session.
Exploitation
Not listed in CISA KEV and no ransomware use documented. EPSS 30-day probability is 0.67848 (99.3rd percentile), indicating high predicted likelihood, and references include vendor advisory and patch commits.
What to do
- Apply the vendor patch referenced in pfSense-SA-23_11 and the linked commits; upgrade pfSense Plus and pfSense CE to fixed releases.
- Restrict web GUI access to trusted management networks and disable WAN-side GUI exposure.
- Enforce least privilege on GUI accounts and remove unused or low-privilege accounts that can reach packet_capture.php.
- Monitor vendor advisory and issue tracker for updated guidance and any revised affected version list.
Detection
- Review web GUI logs for unusual or malformed requests to packet_capture.php.
- Alert on unexpected processes or command execution spawned by the web GUI/PHP process.
- Audit GUI account activity for logins or actions from unusual source addresses.
- Monitor for changes to firewall configuration or packet capture settings outside normal admin activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.netgate.com/downloads/pfSense-SA-23_11.webgui.asc | Vendor Advisory |
| https://github.com/pfsense/pfsense/commit/f72618c4abb61ea6346938d0c93df9078736b775 | Patch |
| https://redmine.pfsense.org/issues/14809 | Issue TrackingPatch |
| https://docs.netgate.com/downloads/pfSense-SA-23_11.webgui.asc | Vendor Advisory |
| https://github.com/pfsense/pfsense/commit/f72618c4abb61ea6346938d0c93df9078736b775 | Patch |
| https://redmine.pfsense.org/issues/14809 | Issue TrackingPatch |
Track CVE-2023-48123 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-48123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.