← Vulnerability feed

Vulnerability record · CVE-2023-48123 · published 6 December 2023

CVE-2023-48123: pfSense web GUI packet_capture.php remote code execution

Netgate · Pfsense

pfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.php. The flaw is in the web GUI and carries a CVSS 3.1 base score of 8.8 (HIGH). The record gives no CWE detail beyond 'insufficient information', so the exact root cause is not stated.

8.8 CVSS 3.1 High EPSS 68% · top 0.7%
8.8CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution on a perimeter firewall with a CVSS of 8.8 and very high EPSS, though it requires low privileges and no public exploit is confirmed in the record.

What it is

pfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.php. The flaw is in the web GUI and carries a CVSS 3.1 base score of 8.8 (HIGH). The record gives no CWE detail beyond 'insufficient information', so the exact root cause is not stated.

Impact

An attacker with the required privileges can run arbitrary code on the firewall, gaining full control of confidentiality, integrity and availability of the device. Because pfSense is a perimeter appliance, compromise can expose or redirect network traffic.

Attack surface

Reachable over the network via the web GUI (AV:N, AC:L), requiring low privileges (PR:L) and no user interaction (UI:N). The crafted request targets packet_capture.php, so the attacker needs at least an authenticated GUI session.

Exploitation

Not listed in CISA KEV and no ransomware use documented. EPSS 30-day probability is 0.67848 (99.3rd percentile), indicating high predicted likelihood, and references include vendor advisory and patch commits.

What to do

  • Apply the vendor patch referenced in pfSense-SA-23_11 and the linked commits; upgrade pfSense Plus and pfSense CE to fixed releases.
  • Restrict web GUI access to trusted management networks and disable WAN-side GUI exposure.
  • Enforce least privilege on GUI accounts and remove unused or low-privilege accounts that can reach packet_capture.php.
  • Monitor vendor advisory and issue tracker for updated guidance and any revised affected version list.

Detection

  • Review web GUI logs for unusual or malformed requests to packet_capture.php.
  • Alert on unexpected processes or command execution spawned by the web GUI/PHP process.
  • Audit GUI account activity for logins or actions from unusual source addresses.
  • Monitor for changes to firewall configuration or packet capture settings outside normal admin activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-48123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27100Netgate pfsense plus improper restriction of authentication attempts vulnerabilityImproper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software…EPSS 9.8%9.8CVE-2019-16915Netgate pfsense path traversal vulnerabilityAn issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e…EPSS 3.7%9.8CVE-2019-12585Apcupsd os command injection vulnerabilityApcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.EPSS 5.0%9.6CVE-2020-21487Netgate pfsense cross-site scripting vulnerabilityCross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFol…EPSS 0.67%8.8CVE-2024-54780Netgate pfsense ce code injection vulnerabilityNetgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to impro…EPSS 12%8.8CVE-2023-42326pfSense WebGUI GIF/GRE Interface Command InjectionNetgate pfSense 2.7.0 contains a command injection flaw in the interfaces_gif_edit.php and interfaces_gre_edit.php WebGUI components. A remote attack…EPSS 64%analysed8.8CVE-2023-27253pfSense restore_rrddata() command injection via crafted XML configNetgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to…EPSS 90%analysed8.8CVE-2022-24299Netgate pfsense improper input validation vulnerabilityImproper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2023-48123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.