← Vulnerability feed

Vulnerability record · CVE-2025-34312 · published 28 October 2025

CVE-2025-34312: Ipfire os command injection vulnerability

Ipfire · Ipfire

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist. When a blacklist is installed the application issues an HTTP POST to /cgi-bin/urlfilter.cgi and interpolates the value of BE_NAME directly into a shell invocation without appropriate sanitation. Crafted input can inject shell metacharacters, leading to arbitrary command execution in the context of the 'nobody' user.

8.7 CVSS 4.0 High EPSS 2.3% · top 17.4% CWE-78 · OS command injection
8.7CVSS 4.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
26 Sep 2026Last modified by NVD

Description

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist. When a blacklist is installed the application issues an HTTP POST to /cgi-bin/urlfilter.cgi and interpolates the value of BE_NAME directly into a shell invocation without appropriate sanitation. Crafted input can inject shell metacharacters, leading to arbitrary command execution in the context of the 'nobody' user.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34312 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-33393IPFire backup script ownership flaw enables root code executionIPFire 2.25-core155 does not verify that /var/ipfire/backup/bin/backup.pl is owned by root, so the file may be writable by an unprivileged account. A…EPSS 60%analysed8.8CVE-2018-16232Ipfire os command injection vulnerabilityAn authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated us…EPSS 7.8%8.8CVE-2017-9757Ipfire os command injection vulnerabilityIPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited…EPSS 37%8.7CVE-2025-34311Ipfire os command injection vulnerabilityIPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …EPSS 14%7.1CVE-2025-34304Ipfire sql injection vulnerabilityIPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL que…EPSS 0.39%6.5CVE-2025-50974Ipfire os command injection vulnerabilityThe Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating p…EPSS 0.40%6.1CVE-2025-50976Ipfire cross-site scripting vulnerabilityIPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query param…EPSS 0.23%6.1CVE-2020-21142Ipfire cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2025-34312), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.